Unsolved

This post is more than 5 years old

8 Posts

633

September 30th, 2006 00:00

Hijack This Symptoms

Logfile of HijackThis v1.99.1
Scan saved at 8:23:42 PM, on 9/29/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\WgaTray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\gary johnson\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0854D220-A90A-466D-BC02-6683183802B7} (PrintPreview Class) - http://lgvboard.fnismls.com/Paragon/Codebase/FNISPrintControl.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 
 
 
I have dealt with an intruder ever since I bought this computer two years ago.  What's scary is that they seem to be able to do things to it when its not even connected to the internet, even though I have nothing wireless on the system.  There seems to be extra things loaded in "component services" and "services".  Please help.  Thanks.

3.3K Posts

October 1st, 2006 18:00

Your log is showing no malware symptoms present. Please explain in greater detail what you've experienced when you say:

Quote:
I have dealt with an intruder ever since I bought this computer two years ago. What's scary is that they seem to be able to do things to it when its not even connected to the internet, even though I have nothing wireless on the system. There seems to be extra things loaded in "component services" and "services".
Exactly what "extra things" are loaded and why do you think there has been an intrusion?
From looking at your log I can see how it would be possible since you have neither an antivirus application nor a third party firewall running, but the log itself shows no signs of anything out of the ordinary.


Please Move HijackThis! To A Permanent Folder

When you installed HijackThis, it installed to a temporary folder. Creating a permanent folder will ensure that HijackThis is not accidentally deleted when we clean out these directories.

1. Click on "My Computer -> C:". Under the File menu, please click "New -> Folder"
2. Rename the new folder (for example, type "HJT" without the quotes) and move the HijackThis.exe file into the new directory.

Your Java application is out of date and causes a slight security risk as a result.
Please follow these steps to remove older version Java components

1. Close any open programs you may have running, especially your web
browser.

2. Click Start-->Control Panel-->Add or Remove Programs.
For those just reading this thread:
Depending on your OS, you may have to click Start-->Settings-->Control Panel-->Add or Remove Programs.


3. Click once on any item listing Java Runtime Environment in the name (to highlight it) then click the "Remove" or "Change/Remove" button.
Not every version of Java will begin with "Java" so be sure to read each entry in the list.
Repeat step 3 as many times as necessary to remove all versions of Java.
**If you are asked to reboot at any point during the uninstallations, please do so. Then go back to Add/Remove and continue with the rest of the removals...when finished uninstalling all of them, reboot the computer.

4. Navigate to and delete:
  • C:\Program Files\ Java =this folder if found
5. Then go to this page.
Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications"and click the "Download" button to the right.

6. Check the box that says: "Accept License Agreement" the page will refresh and click on the link to download Windows Offline Installation with or without Multi-language. Save it to your desktop.
Then from your desktop double-click on jre-1_5_0_09-windowsi586-p.exe to install the newest version.

8 Posts

October 4th, 2006 00:00

Thanks for telling me about Java.  I have been extremely busy with work, so I am just now writing a reply.  I wanted to try to explain a little more of what I've been through, even though I'm fairly new to all of this.  When I posted the log as a "new message,"  it came up on the screen with a green arrow in fornt of the folder as if it were a reply.  To the far right of the folder, next to the title of the message I sent, was a yellow box with the initials U(niform) R(esource) L(ocator).  As far as not having a third party firewall and anti-virus software, I have been using E-Trust anti-virus and Zone Alarm.  I recently had to reformat because of this entitiy (who can also shut my computer down at-will).  I saw this forum on DELL's website, and thought that I would try it before installing Norton Internet Security 2003, which I recently bought.  A program I stopped after the reformat is MSDTC.  Is is set up to run continuously with all the programs that are on the computer.  Ocasionally, I find programs that have been activated in ODBC, and I have to delete them.  Numerous times, when I am at the computer, the surge protector signals that it has been "tripped".  Usually when this happens, an extra svchost.exe program has been placed in the task manager and is running.  I delete it and after some time , it will reappear, running again.  I have gone to a website by the name of grc.com to check my internet security.   This is a reputable website.  Their system said that my system was being used as a "server."  Any other thoughts or suggestions you can give would be greatly appreciated!  Thanks.

3.3K Posts

October 4th, 2006 11:00

Please download:
Dr.Web Cure it.
Double click on the cureit.exe then click "Start".

During the scan infected files are cured, incurable files are moved to the quarantine directory. When the scanning is finished, the log file and the quarantined item/s will not be deleted. Once you determine that the quarantined file is indeed bad, you must manually delete it/them.

To scan your computer with the most up-to-date Dr.Web virus bases next time you scan, you should download a new Dr.Web CureIt! package. To do this, press the "Update" link on the first utility screen, which leads to the ftp-server where the latest version of CureIt! is located. Download the utility anew and run it again. Be sure to delete the out dated version each time.

Please post back the contents of the log generated during the scan along with a fresh HijackThis log. Thanks!

8 Posts

October 6th, 2006 20:00

I just wanted to let you know that I plan on doing what you have suggested.  The only problem is that I have been taking some graduate classes for almost a year now.  They consist of classroom hours and on-line classes.  I have approximately 5 -6 weeks left before I am through with them.  I am very afraid to do anything else (that could put me in jeopardy at the end of these classes) to my computer, since I've already had to reformat, almost lost my data, etc.  I would like to hold off until these classes are finished.  Could you still work with me at that time?  I would keep in touch with you and let you know anything that you needed to know during the break.  I still desperately need your advice and guidance.  Please write me back and I appreciate your help.  Thanks.  

3.3K Posts

October 6th, 2006 22:00

As some malware has a tendancy to mutate it would be in your best interest to post a new thread along with a fresh HijackThis log at that time.
No Events found!

Top