UNSOLVED

mstunkel

updated

21 years ago

M

mstunkel

6 Posts

0

3567

March 14th, 2005 00:00

slow computer. hijackhis log

Logfile of HijackThis v1.99.1
Scan saved at 8:50:57 PM, on 3/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\Warez P2P Client\warez.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\D-Link\AirPlus G Wireless Adapter Utility\AirPlus.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Dell\AccessDirect\DadTray.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Netscape\Netscape Browser\netscape.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\HijackThis-2.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://minisearch.startnow.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://minisearch.startnow.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startnow.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://minisearch.startnow.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com/
R3 - URLSearchHook: HyperSearchHook - {78EB9B34-C66B-462B-BEEB-231A36D21AA7} - C:\Program Files\Common Files\Hyperbar\HyperbarSS3.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet6_38-1.dll
O2 - BHO: HyperBHO - {4B2F5308-2CB0-40E2-8030-59936ED5D22C} - C:\Program Files\Common Files\Hyperbar\Hyperbar.dll
O2 - BHO: (no name) - {80E94343-D74E-8E7B-019E-6F1D315E90E9} - C:\DOCUME~1\Owner\APPLIC~1\CAMPLI~1\mixanti.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [less locks base win] C:\Documents and Settings\All Users.WINDOWS\Application Data\Wave dent less locks\ViewTest.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKCU\..\Run: [warez] "C:\Program Files\Warez P2P Client\warez.exe" -h
O4 - HKCU\..\Run: [VC LOG] C:\DOCUME~1\Owner\APPLIC~1\ITCH01~1\flapskip.exe
O4 - Global Startup: D-Link AirPlus G Wireless Utility.lnk = ?
O4 - Global Startup: D-Link REG Utility.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
 
  • Midnight Star

    4791 Posts

    210

    0

    Posted March 14th, 2005 05:00

    mstunkel,

    Hello! and welcome to the Dell forums.

    -

    Let's see what we can do...



    Go to www.trendmicro.com, and then:

    1. Click " Free Online Scan".
    2. Click " Scan now, it's free".

    It'll take a few minutes to download (especially with a dialup connection), so be patient. When it's down:

    1. Select all available drives.
    2. Check(tick) " Auto Clean".
    3. Click " Scan".

    When it completes, post back the full filename of any files that cannot be cleaned or deleted.



    Download, unzip to your desktop CWShredder and run it, then:

    1. Click " Check For Update"

    ( If an update isn't available, skip to step #4.)

    2. Click " Click here to Download the upate".
    3. When the new version has been downloaded, click " Save".
    4. Click " Fix ->"




    Go to Add/Remove programs and remove(uninstall) the following, if present:

    NewDotNet

    The above could appear anywhere within the entry. Be careful not to remove any personal or system software.



    If your having a problem uninstalling NewDotNet from your system, or if you have no uninstall entry present in " Add/Remove programs", then let's go directly to their website for removal instructions.



    Next, we need to remove(uninstall) the 'lop' infection by going to here, then downloading and running the uninstaller(s) that relate to the application(s) your wanting to remove. The following selections are available: " Start page", " Search engine", " Accessories Toolbar".

    After uninstalling any (or all) of the above, let's see if we have anything in " Scheduled Tasks":

    Download, unzip and run ScheduledTasks.bat (courtesy of ddeerrff), and when notepad comes up, post the contents back to this thread.



    Now, let's open a command prompt and unregister the dll(s) we're going to remove, by entering the following:

    regsvr32 /u newdotnet6_38-1.dll
    regsvr32 /u Hyperbar.dll

    It's ok, if these aren't found or 'error' out. If you want, just copy and paste the individual lines to the command prompt to save on the typing.



    Run HiJackThis and click " Scan", then check(tick) the following, if present:


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://minisearch.startnow.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://minisearch.startnow.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://minisearch.startnow.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com/

    O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet6_38-1.dll
    O2 - BHO: HyperBHO - {4B2F5308-2CB0-40E2-8030-59936ED5D22C} - C:\Program Files\Common Files\Hyperbar\Hyperbar.dll
    O2 - BHO: (no name) - {80E94343-D74E-8E7B-019E-6F1D315E90E9} - C:\DOCUME~1\Owner\APPLIC~1\CAMPLI~1\mixanti.exe

    O4 - HKLM\..\Run: [less locks base win] C:\Documents and Settings\All Users.WINDOWS\Application Data\Wave dent less locks\ViewTest.exe
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s
    O4 - HKCU\..\Run: [VC LOG] C:\DOCUME~1\Owner\APPLIC~1\ITCH01~1\flapskip.exe
    O4 - Global Startup: D-Link AirPlus G Wireless Utility.lnk = ?
    O4 - Global Startup: D-Link REG Utility.lnk = ?


    Now, with all windows closed except HiJackThis, click " Fix checked".



    Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:

    folders...

    C:\Program Files\NewDotNet
    C:\Program Files\Common Files\Hyperbar
    C:\PROGRA~1\NEWDOT~1

    files...

    C:\DOCUME~1\Owner\APPLIC~1\CAMPLI~1\mixanti.exe
    C:\Documents and Settings\All Users.WINDOWS\Application Data\Wave dent less locks\ViewTest.exe
    C:\DOCUME~1\Owner\APPLIC~1\ITCH01~1\flapskip.exe

    -

    Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're ' in use', try deleting them from " Safe Mode".



    Post back a new log, and let me know how everything goes.

    -

    Mike.
  • Midnight Star

    4791 Posts

    210

    0

    Posted March 15th, 2005 15:00

    mstunkel,

    Your more than welcome!

    -

    Reformatting is another very good an option, and is left entirely up to you. As far as it happening again, you, first would need to understand the 'vector' or way it's getting on your system, otherwise we'd just be 'guessing'. What i'd recommend, is posting that question in a new thread, and getting advice from everyone's own experiences that way, you might find someone who has the same system configuration as you do, and have experienced the exact same problem.

    Good luck,

    Mike.
  • mstunkel

    6 Posts

    210

    0

    Posted March 15th, 2005 15:00

    hey and thinks for replying.  I was thinking, I just got this laptop a month ago and don't have much saved on the hard drive.  What about just re formatting the hard drive.  I've already done this once 2 weeks ago and I' ve heard its not good to reformat it alot of times.  If I do this, will it get rid of all my problems?  What could I install to make sure this doesn't happen again once reformatted?

     

    thanks