Unsolved
This post is more than 5 years old
6 Posts
0
2466
May 21st, 2004 15:00
I need help analyzing this hijackthis log
I need help analyzing this hijackthis log:
Lately my computer has slowed down and now when not connected to my ISP, my mouse's cursor shows the hourglass symbol as well. When connected to my ISP the busy symbol goes away...so i'm thinking that i've got some sort of spyware on my system. Here is my hijackthis log, if someone could help me that we be great.
Logfile of HijackThis v1.97.7
Scan saved at 10:05:26 PM, on 05/20/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\SYSTEM32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\spoolsv.exe
D:\WINNT\System32\CTsvcCDA.EXE
D:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
D:\WINNT\System32\svchost.exe
D:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\WINNT\System32\nvsvc32.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\system32\stisvc.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\System32\MsPMSPSv.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\System32\inetsrv\inetinfo.exe
D:\WINNT\Explorer.EXE
D:\WINNT\system32\devldr32.exe
D:\Program Files\Creative\SBLive2k\AudioHQ\AHQTB.EXE
D:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
E:\Program Files\W2K\Winamp3\winampa.exe
D:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
D:\WINNT\system32\internat.exe
D:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
D:\Program Files\Common files\WinTools\WSup.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Internet Explorer\IEXPLORE.EXE
G:\Noel\HijackThis.exe
D:\Program Files\Common files\WinTools\WToolsA.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = D:\WINNT\system32\searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50017
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://localhost/Ketler/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = D:\WINNT\system32\blank.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = D:\WINNT\system32\blank.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = D:\WINNT\system32\searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = D:\WINNT\system32\searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = D:\WINNT\system32\searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50017
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://e-plus.cc/search.php?aff_id=46&keyword=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = D:\WINNT\system32\searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50017
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - D:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://localhost/Ketler/index.html"); (D:\Documents and Settings\Noel\Application Data\Mozilla\Profiles\default\fh99yxwq.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://D%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (D:\Documents and Settings\Noel\Application Data\Mozilla\Profiles\default\fh99yxwq.slt\prefs.js)
O1 - Hosts: 209.17.144.89 noel.com
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - D:\WINNT\twaintec.dll
O2 - BHO: (no name) - {63B78BC1-A711-4D46-AD2F-C581AC420D41} - D:\PROGRA~1\COMMON~1\WinTools\btiein.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - D:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - D:\PROGRA~1\Toolbar\toolbar.dll
O2 - BHO: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - D:\PROGRA~1\COMMON~1\BTLINK\btlink.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - D:\PROGRA~1\Toolbar\toolbar.dll
O3 - Toolbar: PopUpCop - {DB43E4E6-FF8A-4018-8C8E-F68587A44A73} - D:\PROGRA~1\POPUPCOP\PopUpCop.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [UpdReg] D:\WINNT\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] D:\Program Files\Creative\SBLive2k\Program\AHQInit.exe
O4 - HKLM\..\Run: [AudioHQ] D:\Program Files\Creative\SBLive2k\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [NeroCheck] D:\WINNT\System32\NeroCheck.exe
O4 - HKLM\..\Run: [SENTRY] D:\WINNT\SENTRY.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3200] D:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [Ink Monitor] D:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\program files\w2k\quicktime6\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] "E:\Program Files\W2K\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [WinTools] D:\Program Files\Common files\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [alchem] D:\WINNT\alchem.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Startup: PowerReg SchedulerV2.exe
O4 - Global Startup: Aveo Attune.lnk = D:\Program Files\U.S. Robotics\ControlCenter\atmdlusr.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Monitor Apache Servers.lnk = D:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
O8 - Extra context menu item: Open Image in New Window - res://D:\Program Files\PopUpCop\popupcop.dll/imagenew
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {018B7EC3-EECA-11D3-8E71-0000E82C6C0D} - http://www.lyricsdomain.com/download.mp3.exe
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38115.8062731481
O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_03) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash2/cabs/swflash.cab
Thanks,
nmmh1024


ChrisRLG
2 Intern
•
3.9K Posts
0
May 22nd, 2004 22:00
=====================
Download then unzip and run CWShredder to clean up clicking FIX to have it remove all it finds.
cwshredder from here
or from here
or download page from here
Please run in safe mode (F8 at boot time)
How to start the computer in Safe mode
Reboot then
Spybot S&D and Ad-aware using the settings and links provided
Here
please post a new hijackthis log after a reboot.
nmmh1024
6 Posts
0
May 24th, 2004 17:00
This is a great forum, thanks so much for all the links and detailed and accurate information on how to go about handling Spy stuff.
Also, I forgot to mention that the computer problems i was having are gone (computer is now booting quicker and the hourglass symbol has gone. I've now just run CWShredder and it removed CWSmartSearch and 5 IE registry values. My Hijackthis log now is:
Logfile of HijackThis v1.97.7
Scan saved at 11:58:49 AM, on 05/24/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\SYSTEM32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\spoolsv.exe
E:\PROGRA~1\W2K\Grisoft\AVG6\avgserv.exe
D:\WINNT\System32\CTsvcCDA.EXE
D:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
D:\WINNT\System32\svchost.exe
D:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\WINNT\System32\nvsvc32.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\system32\stisvc.exe
D:\WINNT\system32\ZONELABS\vsmon.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\System32\MsPMSPSv.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\System32\inetsrv\inetinfo.exe
D:\WINNT\Explorer.EXE
D:\WINNT\system32\devldr32.exe
D:\Program Files\Creative\SBLive2k\AudioHQ\AHQTB.EXE
D:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
E:\Program Files\W2K\Winamp3\winampa.exe
D:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
E:\PROGRA~1\W2K\Grisoft\AVG6\avgcc32.exe
D:\WINNT\system32\internat.exe
D:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
D:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
D:\WINNT\system32\mmc.exe
D:\WINNT\system32\mmc.exe
E:\Program Files\W2K\EditPlus211a\editplus.exe
E:\Original Files\Software Exe\Security - Spy Removal\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://localhost/Ketler/index.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://localhost/Ketler/index.html"); (D:\Documents and Settings\Noel\Application Data\Mozilla\Profiles\default\fh99yxwq.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://D%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (D:\Documents and Settings\Noel\Application Data\Mozilla\Profiles\default\fh99yxwq.slt\prefs.js)
O1 - Hosts: 209.17.144.89 noel.com
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\System32\msdxm.ocx
O3 - Toolbar: PopUpCop - {DB43E4E6-FF8A-4018-8C8E-F68587A44A73} - D:\PROGRA~1\POPUPCOP\PopUpCop.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [UpdReg] D:\WINNT\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] D:\Program Files\Creative\SBLive2k\Program\AHQInit.exe
O4 - HKLM\..\Run: [AudioHQ] D:\Program Files\Creative\SBLive2k\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [NeroCheck] D:\WINNT\System32\NeroCheck.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3200] D:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [Ink Monitor] D:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\program files\w2k\quicktime6\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] "E:\Program Files\W2K\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [AVG_CC] E:\PROGRA~1\W2K\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Startup: PowerReg SchedulerV2.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Monitor Apache Servers.lnk = D:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = D:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O8 - Extra context menu item: Open Image in New Window - res://D:\Program Files\PopUpCop\popupcop.dll/imagenew
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38115.8062731481
O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_03) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash2/cabs/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FE983AFA-54F6-44D4-9105-BBC632761DC5}: NameServer = 209.139.247.254 209.53.200.2
nmmh1024
6 Posts
0
May 24th, 2004 17:00
Thanks for responding Chris!
Well, I've been reading a lot of the posts that yourself and others have replied to, in the meantime and the details of what the lines in HijackThis means. So I ended up trying to fix. What I did was installed and run the latest Spybot version, Adaware, and AVG Virus software. Primarily the AVG software fixed most of the many problems. So then i ran Hijackthis again then still noticed some of the WinTools and that still there. So i rebooted into Safe mode then ran Hijackthis to remove those problems and also manually. So now i'm ended up with a report shown below:
Logfile of HijackThis v1.97.7
Scan saved at 11:45:13 AM, on 05/24/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\SYSTEM32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\spoolsv.exe
E:\PROGRA~1\W2K\Grisoft\AVG6\avgserv.exe
D:\WINNT\System32\CTsvcCDA.EXE
D:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
D:\WINNT\System32\svchost.exe
D:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\WINNT\System32\nvsvc32.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\system32\stisvc.exe
D:\WINNT\system32\ZONELABS\vsmon.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\System32\MsPMSPSv.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\System32\inetsrv\inetinfo.exe
D:\WINNT\Explorer.EXE
D:\WINNT\system32\devldr32.exe
D:\Program Files\Creative\SBLive2k\AudioHQ\AHQTB.EXE
D:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
E:\Program Files\W2K\Winamp3\winampa.exe
D:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
E:\PROGRA~1\W2K\Grisoft\AVG6\avgcc32.exe
D:\WINNT\system32\internat.exe
D:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
D:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
D:\WINNT\system32\mmc.exe
D:\WINNT\system32\mmc.exe
E:\Program Files\W2K\EditPlus211a\editplus.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\WINNT\system32\notepad.exe
E:\Original Files\Software Exe\Security - Spy Removal\CWShredder.exe
E:\Original Files\Software Exe\Security - Spy Removal\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = D:\WINNT\system32\searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://localhost/Ketler/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = D:\WINNT\system32\searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = D:\WINNT\system32\searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = D:\WINNT\system32\searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = D:\WINNT\system32\searchbar.html
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://localhost/Ketler/index.html"); (D:\Documents and Settings\Noel\Application Data\Mozilla\Profiles\default\fh99yxwq.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://D%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (D:\Documents and Settings\Noel\Application Data\Mozilla\Profiles\default\fh99yxwq.slt\prefs.js)
O1 - Hosts: 209.17.144.89 noel.com
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\System32\msdxm.ocx
O3 - Toolbar: PopUpCop - {DB43E4E6-FF8A-4018-8C8E-F68587A44A73} - D:\PROGRA~1\POPUPCOP\PopUpCop.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [UpdReg] D:\WINNT\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] D:\Program Files\Creative\SBLive2k\Program\AHQInit.exe
O4 - HKLM\..\Run: [AudioHQ] D:\Program Files\Creative\SBLive2k\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [NeroCheck] D:\WINNT\System32\NeroCheck.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3200] D:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [Ink Monitor] D:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\program files\w2k\quicktime6\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] "E:\Program Files\W2K\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [AVG_CC] E:\PROGRA~1\W2K\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Startup: PowerReg SchedulerV2.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Monitor Apache Servers.lnk = D:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = D:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O8 - Extra context menu item: Open Image in New Window - res://D:\Program Files\PopUpCop\popupcop.dll/imagenew
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38115.8062731481
O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_03) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash2/cabs/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FE983AFA-54F6-44D4-9105-BBC632761DC5}: NameServer = 209.139.247.254 209.53.200.2
I've just now read your reply and have downloaded and run CWShredder and it still notices infections for CoolWeb...I'll put another reply to show the results after CWShredder
ChrisRLG
2 Intern
•
3.9K Posts
0
May 25th, 2004 20:00
Sorry for delay in reply - lots of posts and so little time
I assume this has been set by you - so will not suggest its fix - If I am wrong please let me know.
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://localhost/Ketler/index.html
==============================
Check these in hijackthis, AND WITH ALL OTHER WINDOWS CLOSED, fix checked.
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Startup: PowerReg SchedulerV2.exe
(Last is a program register nag reminder - optional)
Then Reboot to safe mode (F8 on boot) and delete the following files/folders:-
NOTE: To avoid the risk of any of the above not being found due to them having the 'Hidden' attribute, first make sure that in Folder Options > View hidden and operating system files are set to show:
How to Show Hidden/System Files : http://www.xtra.co.nz/help/0,,4155-1916458,00.html
File > > D:\WINNT\system32\internat.exe
Then Reboot and post a fresh log for me to check.
nmmh1024
6 Posts
0
May 26th, 2004 13:00
Here's the latest log with the fixes you mentioned. And yes, the http://localhost/Ketler/index.html is a homepage that I am making so no worries.
Logfile of HijackThis v1.97.7
Scan saved at 7:38:54 AM, on 05/26/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\SYSTEM32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\spoolsv.exe
E:\PROGRA~1\W2K\Grisoft\AVG6\avgserv.exe
D:\WINNT\System32\CTsvcCDA.EXE
D:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
D:\WINNT\System32\svchost.exe
D:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\WINNT\System32\nvsvc32.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\system32\stisvc.exe
D:\WINNT\system32\ZONELABS\vsmon.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\System32\MsPMSPSv.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\System32\inetsrv\inetinfo.exe
D:\WINNT\Explorer.EXE
D:\WINNT\system32\devldr32.exe
D:\Program Files\Creative\SBLive2k\AudioHQ\AHQTB.EXE
D:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
E:\Program Files\W2K\Winamp3\winampa.exe
D:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
E:\PROGRA~1\W2K\Grisoft\AVG6\avgcc32.exe
D:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
D:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
D:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://localhost/Ketler/index.html
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://localhost/Ketler/index.html"); (D:\Documents and Settings\Noel\Application Data\Mozilla\Profiles\default\fh99yxwq.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://D%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (D:\Documents and Settings\Noel\Application Data\Mozilla\Profiles\default\fh99yxwq.slt\prefs.js)
O1 - Hosts: 209.17.144.89 noel.com
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\System32\msdxm.ocx
O3 - Toolbar: PopUpCop - {DB43E4E6-FF8A-4018-8C8E-F68587A44A73} - D:\PROGRA~1\POPUPCOP\PopUpCop.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [UpdReg] D:\WINNT\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] D:\Program Files\Creative\SBLive2k\Program\AHQInit.exe
O4 - HKLM\..\Run: [AudioHQ] D:\Program Files\Creative\SBLive2k\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [NeroCheck] D:\WINNT\System32\NeroCheck.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3200] D:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [Ink Monitor] D:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\program files\w2k\quicktime6\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] "E:\Program Files\W2K\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [AVG_CC] E:\PROGRA~1\W2K\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Monitor Apache Servers.lnk = D:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = D:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O8 - Extra context menu item: Open Image in New Window - res://D:\Program Files\PopUpCop\popupcop.dll/imagenew
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38115.8062731481
O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_03) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash2/cabs/swflash.cab
Thanks Chris,
Regards,
Noel
ChrisRLG
2 Intern
•
3.9K Posts
0
May 26th, 2004 20:00
------------------------
How on earth did I get infected with all that spyware in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051
Also available from here :- http://www.computercops.biz/postlite7736-.html or http://boards.cexx.org/viewtopic.php?t=957
--------------
Look at the info on my website regarding malware (Link below). Some things you can do to stop getting infected again:-
Spybot S&D, Ad-aware Run weekly - or after a heavy internet session.
Spybot S&D v1.3 also have a run time module that runs in the background.
Spywareblaster & Spywareguard, first sets kill bits to stop known bad activeX controls installing, second acts like your AV to stop browser hijacks and installing of known badies.
Also ie-spyad (Link on my site), puts 4000 bad sites in your restricted (banned) sites list, to stop you accidentaly getting sent to a bad site, it has optional list of "bad" adult sites to install as well.
All those with links from my site. Do remember just like Anti-Virus they need to be updated regularly, I do mine weekly, Anti-Virus hourly.
Another good program winpatrol from here.
With these and a firewall in place I have to try various bad sites when checking peoples hijackthis logs looking to sort bad from good, and I have not yet been infected. Still time for it to happen LOL.
nmmh1024
6 Posts
0
May 27th, 2004 14:00
Great! =)
Thanks for taking the time out to help.
Definitely I'll run the Spybot v1.3 and adaware frequently, along with having AVG virus software, and a Zone Alarm Pro firewall.
Noel
ChrisRLG
2 Intern
•
3.9K Posts
0
May 27th, 2004 15:00
Your welcome
BTW
Spywareguard, ie-Spyad, Winpatrol and Spywareblaster are PROactive against spyware
Sypbot S&D and Ad-aware are REactive. (Spybot v1.3 teatimer is Proactive)
Reactive = after you are infected
Proactive = BEFORE you get infected.
I run with all those programs I suggest.