Unsolved

This post is more than 5 years old

9 Posts

555

October 28th, 2005 21:00

I keep getting time outs on random websites

Have I contracted some spyware? My machine has slowed down and I have been getting "this operation has timed out." Here's my log.

Thank you,
Betty
Logfile of HijackThis v1.99.1
Scan saved at 1:41:14 PM, on 10/28/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\iRiver\iRiver Manager\Updater\Updater.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\CoffeeCup Software\PopUp Blocker\PopupBlocker.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\gearsec.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\mozilla.org\Mozilla\mozilla.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\HJT\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.bellsouth.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: CoffeeCup Software Popup Blocker - {49E0E0F0-5C30-11D4-945D-010002000012} - C:\PROGRA~1\COFFEE~1\POPUPB~1\CCPOPB~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iRiver Updater] C:\Program Files\iRiver\iRiver Manager\Updater\Updater.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Startup: CoffeeCup Popup Blocker.lnk = C:\Program Files\CoffeeCup Software\PopUp Blocker\PopupBlocker.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ResQNet - https://www.fabricut.net/ResQNet/cclient.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C28BAF35-B567-44C7-ABBF-5D8D8117ECAE}: NameServer = 38.9.211.2,38.9.212.2
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

November 6th, 2005 20:00

Hello betty818,

Sorry it is taken so long for anyone to respond. Everyone who helps out around here is a volunteer and often there are just not enough of us to keep up.

If you still would like assistance, please post a fresh HijackThis log so that we are working with the most current data. I will be happy to take a look at it for you.:smileyhappy:

George a.k.a. SpotCheckBilly

9 Posts

November 6th, 2005 23:00

Ok, no problem about the delay. Ya'll have got me out of big jam in the past and I appreciate the work you do. Here is the latest logfile. When my husband launches IE, the status bar displays a message that says "Served by advertising.com". (I use mozilla)

Thanks,
Betty Ross

Logfile of HijackThis v1.99.1
Scan saved at 8:07:26 PM, on 11/6/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\iRiver\iRiver Manager\Updater\Updater.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\CoffeeCup Software\PopUp Blocker\PopupBlocker.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\gearsec.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Adobe\Photoshop Elements

3.0\PhotoshopElementsDeviceConnect.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\cidaemon.exe
C:\HJT\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

http://home.bellsouth.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet

Settings,ProxyOverride = 127.0.0.1
O2 - BHO: CoffeeCup Software Popup Blocker -

{49E0E0F0-5C30-11D4-945D-010002000012} -

C:\PROGRA~1\COFFEE~1\POPUPB~1\CCPOPB~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program

Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -

c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -

C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} -

C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program

files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program

Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [diagent] "C:\Program

Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client

Foundation\CFD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe"

-atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe

-CheckReg
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common

Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iRiver Updater] C:\Program Files\iRiver\iRiver

Manager\Updater\Updater.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE

C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft

ActiveSync\WCESCOMM.EXE"
O4 - Startup: CoffeeCup Popup Blocker.lnk = C:\Program Files\CoffeeCup

Software\PopUp Blocker\PopupBlocker.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common

Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program

Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program

Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft

Office\Office10\OSA.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program

Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common

Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM

Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program

files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program

files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program

files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program

files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel -

res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program

files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program

files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Create Mobile Favorite -

{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft

ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} -

C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... -

{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft

ActiveSync\INetRepl.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program

Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet

Explorer\Plugins\NPDocBox.dll
O16 - DPF: ResQNet - https://www.fabricut.net/ResQNet/cclient.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload

Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O17 -

HKLM\System\CCS\Services\Tcpip\..\{C28BAF35-B567-44C7-ABBF-5D8D8117ECAE}:

NameServer = 38.9.211.2,38.9.212.2
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown

owner - C:\Program Files\Adobe\Photoshop Elements

3.0\PhotoshopElementsFileAgent.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. -

C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. -

C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd -

C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program

Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software -

C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program

Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -

C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Photoshop Elements Device Connect

(PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program

Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

November 7th, 2005 06:00

hello Betty ,

The good news is your log looks clean. I think a good cleanup will help. Please do this:

Download CCleaner and install.
Configure and run as follows:
  • Open CCleaner.
  • Place a check-mark next to:
  • Eeverything in the Applications tab.
  • Place a check-mark next to:
    • Internet Explorer
    • Windows explorer and
    • System, in the Windows tab.
    • Hit Run CCleaner
    • Reboot to remove index.dat files.


      Go to www.trendmicro.com, then:

      1. Click " Free Online Scan".
      2. Click " Scan now, it's free".

      Follow the screen prompts.

      Save a copy of the report,:
      Click " Print the report", then copy/paste to a new Notepad file and save to a convenient location. Post results into the next reply if requested to do so.

      Run HiJackThis and click " Scan", then check(tick) the following, if present:

      O17 - HKLM\System\CCS\Services\Tcpip\..\{C28BAF35-B567-44C7-ABBF-5D8D8117ECAE}: NameServer = 38.9.211.2,38.9.212.2
      ...( Verify that these ip addresses are for your isp's DNS Servers, if so, don't 'fix' these.)

      With all windows closed except HiJackThis, click " Fix checked".

      Post back a new log, along with the results of the online scan.

      Let me know if everything is running OK. :smileyhappy:

      George a.k.a. SpotCheckBilly.

      9 Posts

      November 8th, 2005 23:00

      Hello Spot Check Billy,

      I followed your directions and did indeed have to "fix" the item you predicted. Thanks for your help. Should I run CCCleaner and TrendMicro on my computer and my kids computer from time to time?

      Thanks,
      Betty
      Logfile of HijackThis v1.99.1
      Scan saved at 7:58:51 PM, on 11/8/2005
      Platform: Windows XP SP1 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      C:\WINDOWS\system32\cisvc.exe
      C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
      C:\Program Files\BroadJump\Client Foundation\CFD.exe
      C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\WINDOWS\System32\CTsvcCDA.exe
      C:\Program Files\ewido\security suite\ewidoctrl.exe
      C:\WINDOWS\SM1BG.EXE
      C:\WINDOWS\System32\gearsec.exe
      C:\WINDOWS\System32\nvsvc32.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\Adobe\Photoshop Elements

      3.0\PhotoshopElementsDeviceConnect.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
      C:\Program Files\iRiver\iRiver Manager\Updater\Updater.exe
      C:\WINDOWS\System32\RUNDLL32.EXE
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
      C:\WINDOWS\System32\MsPMSPSv.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
      C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
      C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
      C:\WINDOWS\System32\HPZipm12.exe
      C:\WINDOWS\System32\wuauclt.exe
      C:\WINDOWS\system32\cidaemon.exe
      C:\HJT\hijackthis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

      http://home.bellsouth.net/
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet

      Settings,ProxyOverride = 127.0.0.1
      O2 - BHO: CoffeeCup Software Popup Blocker -

      {49E0E0F0-5C30-11D4-945D-010002000012} -

      C:\PROGRA~1\COFFEE~1\POPUPB~1\CCPOPB~1.DLL
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program

      Files\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -

      c:\program files\google\googletoolbar2.dll
      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -

      C:\WINDOWS\System32\msdxm.ocx
      O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} -

      C:\Program Files\AIM Toolbar\AIMBar.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program

      files\google\googletoolbar2.dll
      O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program

      Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
      O4 - HKLM\..\Run: [diagent] "C:\Program

      Files\Creative\SBLive\Diagnostics\diagent.exe" startup
      O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

      C:\WINDOWS\System32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client

      Foundation\CFD.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe"

      -atboottime
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
      O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe

      -CheckReg
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common

      Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
      O4 - HKLM\..\Run: [iRiver Updater] C:\Program Files\iRiver\iRiver

      Manager\Updater\Updater.exe
      O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE

      C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
      O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft

      ActiveSync\WCESCOMM.EXE"
      O4 - Startup: CoffeeCup Popup Blocker.lnk = C:\Program Files\CoffeeCup

      Software\PopUp Blocker\PopupBlocker.exe
      O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common

      Files\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program

      Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program

      Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft

      Office\Office10\OSA.EXE
      O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program

      Files\Nikon\PictureProject\NkbMonitor.exe
      O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common

      Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
      O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM

      Toolbar\AIMBar.dll/aimsearch.htm
      O8 - Extra context menu item: &Google Search - res://c:\program

      files\google\GoogleToolbar2.dll/cmsearch.html
      O8 - Extra context menu item: &Translate English Word - res://c:\program

      files\google\GoogleToolbar2.dll/cmwordtrans.html
      O8 - Extra context menu item: Backward Links - res://c:\program

      files\google\GoogleToolbar2.dll/cmbacklinks.html
      O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program

      files\google\GoogleToolbar2.dll/cmcache.html
      O8 - Extra context menu item: E&xport to Microsoft Excel -

      res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
      O8 - Extra context menu item: Similar Pages - res://c:\program

      files\google\GoogleToolbar2.dll/cmsimilar.html
      O8 - Extra context menu item: Translate Page into English - res://c:\program

      files\google\GoogleToolbar2.dll/cmtrans.html
      O9 - Extra button: Create Mobile Favorite -

      {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft

      ActiveSync\INetRepl.dll
      O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} -

      C:\Program Files\Microsoft ActiveSync\INetRepl.dll
      O9 - Extra 'Tools' menuitem: Create Mobile Favorite... -

      {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft

      ActiveSync\INetRepl.dll
      O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program

      Files\AIM\aim.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

      C:\Program Files\Messenger\MSMSGS.EXE
      O9 - Extra 'Tools' menuitem: Messenger -

      {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

      Files\Messenger\MSMSGS.EXE
      O12 - Plugin for .spop: C:\Program Files\Internet

      Explorer\Plugins\NPDocBox.dll
      O16 - DPF: ResQNet - https://www.fabricut.net/ResQNet/cclient.cab
      O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -

      http://housecall60.trendmicro.com/housecall/xscan60.cab
      O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload

      Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
      O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown

      owner - C:\Program Files\Adobe\Photoshop Elements

      3.0\PhotoshopElementsFileAgent.exe
      O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. -

      C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. -

      C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd -

      C:\WINDOWS\System32\CTsvcCDA.exe
      O23 - Service: ewido security suite control - ewido networks - C:\Program

      Files\ewido\security suite\ewidoctrl.exe
      O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software -

      C:\WINDOWS\System32\gearsec.exe
      O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program

      Files\iPod\bin\iPodService.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -

      C:\WINDOWS\System32\nvsvc32.exe
      O23 - Service: Photoshop Elements Device Connect

      (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program

      Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

      November 9th, 2005 06:00

      Hello Betty,

      Congratulations! Your log looks clean - good work!

      ****MOST IMPORTANT****:

      You Need to Update Windows and IE to get Service Pack 2 (sp2)
      and all the Latest Security Patches to protect your computer from the malware that is around on the internet.

      Please go to Microsoft Windows and Internet Explorer Updates to get the critical updates.

      If you are running Microsoft Office, or any portion thereof, go to the Microsoft Office Update site and make sure you have at least all the Cirtical Updates installed (Free) .



      Reboot your computer, and try using different programs and make sure everything is running ok. If you're still experiencing problems, post back a description and wait for advice before continuing with the cleanup.



      Download, install and run Cleanup! from Steven Gould, then:

      1. Click " Cleanup!"

      ( wait for the program to finish scanning your system, and selecting files to be removed.)

      2. Exit the program and reboot the computer, if necessary.

      For more information about using Cleanup! see here.



      If everything is running ok, let's do the final cleanup...



      1. Run " Disk Cleanup" and allow it to remove everything it finds.

      2. If you've downloaded MicroWorld AV ( MWAV), run it again - but don't scan, just click " Clear Log" and exit the program.

      3. Go to www.trendmicro.com and click " Free Online Scan", then " Scan now, it's free!". Follow on-screen prompts.

      4. Run Ad-Aware SE Personal and Spybot Search & Destroy.

      ***Very Important***

      Before you run either of these programs, please update and configure according to the Ad-Aware SE Personal Tutorial and Spybot S&D Tutorial.

      Reboot between each scan. Let them each remove the residual 'problems' that HiJackThis couldn't fix.

      NOTE: Running Ad-Aware SE Personal and SpyBot S&D on a regular basis (I do it twice a week) will go a long way in keeping your computer malware free.

      5. Disable, then re-enable system restore; with a reboot in-between. Then immediately create a new system restore point manually.

      To help prevent further infections, I recommend, and use, SpywareBlaster, SpywareGuard and IE-SPYAD.
      (Links provided in my signature below.).

      SpywareBlaster blocks bad ActiveX and malevolent cookies. IE-SPYAD puts over 4000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all. SpywareGuard provides active real-time protection.

      Once installed, just check frequently for updates .

      Most experts recommend (as I do) that a firewall should be installed
      and used. Two popular free firewalls:
      Zone Alarm and Sygate Personal Firewall.
      (Links provided in my signature below.).

      Also, please see
      So how did I get infected in the first place?



      Yes, in addition to regular sweeps withAd-Aware SE Personal and Spybot S&D, running the online scan and Ccleaner occasionally will keep the clutter to a minimum and keep performance at its best.

      If you are having any more problems, post back the description along with a fresh HijackThis log. :smileyhappy:

      George a.k.a. SpotCheckBilly

      9 Posts

      November 11th, 2005 10:00

      Your "most important" piece of advice was to load Windows SP2. When I did that in the past, it slowed down my wireless connection between my modem and my 2 computers in my home. That's why I removed it. That was also the advice of the Linksys people. Have they made corrections to that problem in the past 6 months?

      Thanks,
      Betty

      November 11th, 2005 21:00

      Hello Betty,

      I have a Linksys router (wireless) as well. I currently have sp2 and all current critical updates. The connection between my router and the three other computers on the network is faster than my cable connection. Do you have the latest firmware updates for your router? How about the wireless cards in the other computers on your network? How much of a slowdown between your computers are you experiencing?

      The other thing to consider here (unless your slowdown is really drastic), is the amount of connection speed loss worth compromising the security of your machines?

      One sort of a side note, the wireless connection between our router and my sons computer averages between 10 MB/second or a little better. My Internet connection, which is cable, runs between 1.0 MB/second and 1.5 MB/second. So even at the average speed, the wireless connection is still right around 10 times faster than my Internet connection.

      Hope this information helps. There is also a wireless networking forum here at Dell with a lot of pretty sure people who are always willing to help :smileyhappy:

      George a.k.a. SpotCheckBilly
      No Events found!

      Top