Jump to content

Hijack This! logs


Steve

Recommended Posts

Logfile of HijackThis v1.99.1

Scan saved at 18:28:07, on 21/02/2006

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\System32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

C:\WINDOWS\System32\ctfmon.exe

C:\Program Files\Microsoft Hardware\Mouse\point32.exe

C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\Documents and Settings\Paul Holness\My Documents\Downloads\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/

F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [POINTER] point32.exe

O4 - HKLM\..\Run: [Windows Word] WINWORD32.EXE

O4 - HKLM\..\Run: [speedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon

O4 - HKLM\..\Run: [Ad-Aware] "C:\PROGRA~1\LAVASOFT\AD-AWA~2\AD-AWARE.EXE" +c

O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [speedTouchstInstall] "C:/Documents and Settings/Paul Holness/Desktop/SetupWizard/stInstall.exe"

O4 - Startup: Karoo.lnk = D:\Start.exe

O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm

O8 - Extra context menu item: Add to AD Black List - C:\Program Files\Avant Browser\AddToADBlackList.htm

O8 - Extra context menu item: Block All Images from the Same Server - C:\Program Files\Avant Browser\AddAllToADBlackList.htm

O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm

O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O8 - Extra context menu item: Highlight - C:\Program Files\Avant Browser\Highlight.htm

O8 - Extra context menu item: Open All Links in This Page... - C:\Program Files\Avant Browser\OpenAllLinks.htm

O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm

O8 - Extra context menu item: Search - C:\Program Files\Avant Browser\Search.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O17 - HKLM\System\CCS\Services\Tcpip\..\{2F1876E1-25BE-4089-9173-4933F8F30001}: NameServer = 212.50.160.100 213.249.130.100

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~2\msgrapp.dll" (file missing)

O20 - Winlogon Notify: debugg - C:\WINDOWS\SYSTEM32\debugg.dll

O21 - SSODL: WebCheck - {E61B5E20-DE35-11CF-9C87-1579005127ED} - (no file)

O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: iPod Service (iPodService) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)

O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe

O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe

O23 - Service: SmartLinkService (SLService) - Unknown owner - slserv.exe (file missing)

Link to comment
Share on other sites

That's better man. You need to fix these: -

 

O20 - Winlogon Notify: debugg - C:\WINDOWS\SYSTEM32\debugg.dll

O21 - SSODL: WebCheck - {E61B5E20-DE35-11CF-9C87-1579005127ED} - (no file)

 

And you need to do the Safe Mode part or they'll keep coming back. One is a virus that allows hackers full access to your PC and as you have no firewall to stop them........

 

You also need to get your Windows Updates man. Service Pack 2 was released months ago and fixes a lot of security issues.

Link to comment
Share on other sites

That's better man. You need to fix these: -

 

O20 - Winlogon Notify: debugg - C:\WINDOWS\SYSTEM32\debugg.dll

O21 - SSODL: WebCheck - {E61B5E20-DE35-11CF-9C87-1579005127ED} - (no file)

 

And you need to do the Safe Mode part or they'll keep coming back. One is a virus that allows hackers full access to your PC and as you have no firewall to stop them........

 

You also need to get your Windows Updates man. Service Pack 2 was released months ago and fixes a lot of security issues.

 

chhers will do

Link to comment
Share on other sites

i got onto safe mode could'nt find tools and folder options. its just like normal but weird.

found debug.dll cant delete it

i got internet explorer icon back but still missing desttop one from quick lauch i deleted it off a while ago cant find away to get it back.

cheers

Edited by Pman
Link to comment
Share on other sites

OK, well you need to get rid of that debugg.dll file. (Note the 2 letter g's in the name - don't delete any other files with similar names!).

 

To get rid of it, do this: -

 

Hit Start, then Run and type "cmd" without quotes and hit Enter. An old DOS style window will open. Type the following commands, pressing enter after each one: -

 

c:

cd\

cd c:\windows\system32

regsvr32 /u debugg.dll

 

In the third command there is a single space after "cd" and in the last command there is a single space either side of "/u". Once you've done that, reboot into Safe Mode again and you should be able to delete the file. If you can't post back again, but either way it has to be gotten rid of as it's a trojan.

 

To restore your Show Desktop icon, download this attachment and unzip the file to your Desktop. Then you can drag it on to the Quick Launch bar: -

 

Show_Desktop.zip

Link to comment
Share on other sites

i got the desktop logo backs thanks alot

 

i did that thing in what looks like dos, it says the registery point was not found so shall i still go in safe mode

go through step by step what i do in safe mode.

cheers

Link to comment
Share on other sites

I tell you what, we'll try it an easier way, because if you didn't get a message saying "the dll has been unregistered" or some shit like that, then chances are you won't be able to delete it in Safe Mode again.

 

Run HijackThis again and instead of clicking the Scan button, click Config on the right. Click the Misc Tools button at the top, then from the menu on the left select Delete A File On Reboot... Browse to the debugg.dll file and select it. You'll get a message saying it'll be deleted next time you reboot and do you want to do that now - select yes and that should be it.

Link to comment
Share on other sites

I tell you what, we'll try it an easier way, because if you didn't get a message saying "the dll has been unregistered" or some shit like that, then chances are you won't be able to delete it in Safe Mode again.

 

Run HijackThis again and instead of clicking the Scan button, click Config on the right. Click the Misc Tools button at the top, then from the menu on the left select Delete A File On Reboot... Browse to the debugg.dll file and select it. You'll get a message saying it'll be deleted next time you reboot and do you want to do that now - select yes and that should be it.

 

Right

i done all that ill post my last hijack log

i'll love you forever if its worked just give us a final overlook

 

Logfile of HijackThis v1.99.1

Scan saved at 22:02:54, on 21/02/2006

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\System32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\wuauclt.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

C:\Program Files\Microsoft Hardware\Mouse\point32.exe

C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe

C:\WINDOWS\System32\ctfmon.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe

C:\PROGRA~1\MOZILL~1\FIREFOX.EXE

C:\Documents and Settings\Paul Holness\My Documents\Downloads\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/

F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe

O2 - BHO: (no name) - {021BB032-80A8-4FB6-B3D5-CF27B1553B95} - (no file)

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {2548e425-a332-4c84-9633-4b3101f7d0bb} - (no file)

O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll

O2 - BHO: (no name) - {4CFD8060-60C8-45A8-8133-4B086C5AE49F} - (no file)

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)

O2 - BHO: (no name) - {B9089D79-F34A-7D76-9427-BF5FF9BABCF1} - (no file)

O2 - BHO: (no name) - {D881967C-B832-4DE8-B844-98D9D055C89A} - (no file)

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [POINTER] point32.exe

O4 - HKLM\..\Run: [Windows Word] WINWORD32.EXE

O4 - HKLM\..\Run: [speedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon

O4 - HKLM\..\Run: [Ad-Aware] "C:\PROGRA~1\LAVASOFT\AD-AWA~2\AD-AWARE.EXE" +c

O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [speedTouchstInstall] "C:/Documents and Settings/Paul Holness/Desktop/SetupWizard/stInstall.exe"

O4 - Startup: Karoo.lnk = D:\Start.exe

O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm

O8 - Extra context menu item: Add to AD Black List - C:\Program Files\Avant Browser\AddToADBlackList.htm

O8 - Extra context menu item: Block All Images from the Same Server - C:\Program Files\Avant Browser\AddAllToADBlackList.htm

O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm

O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O8 - Extra context menu item: Highlight - C:\Program Files\Avant Browser\Highlight.htm

O8 - Extra context menu item: Open All Links in This Page... - C:\Program Files\Avant Browser\OpenAllLinks.htm

O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm

O8 - Extra context menu item: Search - C:\Program Files\Avant Browser\Search.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} -

O16 - DPF: {093F9CF8-0DE1-491C-95D5-5EC257BD4CA3} -

O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540002} -

O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} -

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} -

O16 - DPF: {2AEEAC34-FD74-4142-B891-4B05C0C03C87} -

O16 - DPF: {2C0F2AEA-3A9B-46DB-A7BE-80FF329E415D} -

O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} -

O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} -

O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} -

O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} -

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} -

O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} -

O16 - DPF: {88C51E90-8E9C-4C96-8A45-574D88B63FAF} -

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} -

O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} -

O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} -

O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} -

O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} -

O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} -

O16 - DPF: {CC110316-5BE7-4AAA-AEDD-1A5B147BE34C} -

O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} -

O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} -

O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} -

O16 - DPF: {E154E3CC-0C3A-4101-91D8-6B4876F0FD64} -

O16 - DPF: {EEECA057-AD0F-44A7-8BE5-8634CEDBDBD1} -

O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} -

O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} -

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} -

O17 - HKLM\System\CCS\Services\Tcpip\..\{2F1876E1-25BE-4089-9173-4933F8F30001}: NameServer = 212.50.160.100 213.249.130.100

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~2\msgrapp.dll" (file missing)

O20 - Winlogon Notify: debugg - debugg.dll (file missing)

O21 - SSODL: WebCheck - {E61B5E20-DE35-11CF-9C87-1579005127ED} - (no file)

O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: iPod Service (iPodService) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)

O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe

O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe

O23 - Service: SmartLinkService (SLService) - Unknown owner - slserv.exe (file missing)

 

if there anything ill do that delete on reboot via hijack cheers + could u post a list of program in order of how i should use them this has took forever cheers for your time.

nice one

Link to comment
Share on other sites

Weird. Loads of stuff has come back since you posted the earlier log. We'll get it sorted though. I just noticed that I missed a dodgy file earlier so maybe that is the cause.

 

Fix these in HijackThis: -

 

O2 - BHO: (no name) - {021BB032-80A8-4FB6-B3D5-CF27B1553B95} - (no file)

O2 - BHO: (no name) - {2548e425-a332-4c84-9633-4b3101f7d0bb} - (no file)

O2 - BHO: (no name) - {4CFD8060-60C8-45A8-8133-4B086C5AE49F} - (no file)

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)

O2 - BHO: (no name) - {B9089D79-F34A-7D76-9427-BF5FF9BABCF1} - (no file)

O2 - BHO: (no name) - {D881967C-B832-4DE8-B844-98D9D055C89A} - (no file)

O4 - HKLM\..\Run: [Windows Word] WINWORD32.EXE

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} -

O16 - DPF: {093F9CF8-0DE1-491C-95D5-5EC257BD4CA3} -

O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540002} -

O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} -

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} -

O16 - DPF: {2AEEAC34-FD74-4142-B891-4B05C0C03C87} -

O16 - DPF: {2C0F2AEA-3A9B-46DB-A7BE-80FF329E415D} -

O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} -

O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} -

O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} -

O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} -

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} -

O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} -

O16 - DPF: {88C51E90-8E9C-4C96-8A45-574D88B63FAF} -

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} -

O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} -

O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} -

O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} -

O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} -

O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} -

O16 - DPF: {CC110316-5BE7-4AAA-AEDD-1A5B147BE34C} -

O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} -

O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} -

O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} -

O16 - DPF: {E154E3CC-0C3A-4101-91D8-6B4876F0FD64} -

O16 - DPF: {EEECA057-AD0F-44A7-8BE5-8634CEDBDBD1} -

O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} -

O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} -

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} -

O20 - Winlogon Notify: debugg - debugg.dll (file missing)

O21 - SSODL: WebCheck - {E61B5E20-DE35-11CF-9C87-1579005127ED} - (no file)

 

One you're done, you need to run a search for this file: -

 

WINWORD32.EXE

 

If you can delete it simply then cool, but otherwise use the same HijackThis method you used before. I'm afraid you're gonna have to come back and post another log afterwards, but once your PC is clean I'll tell you some methods to keep it that way.

Link to comment
Share on other sites

cheers steve

hereit is

 

Logfile of HijackThis v1.99.1

Scan saved at 22:17:02, on 21/02/2006

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\System32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

C:\Program Files\Microsoft Hardware\Mouse\point32.exe

C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe

C:\WINDOWS\System32\ctfmon.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe

C:\PROGRA~1\MOZILL~1\FIREFOX.EXE

C:\Documents and Settings\Paul Holness\My Documents\Downloads\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/

F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [POINTER] point32.exe

O4 - HKLM\..\Run: [speedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon

O4 - HKLM\..\Run: [Ad-Aware] "C:\PROGRA~1\LAVASOFT\AD-AWA~2\AD-AWARE.EXE" +c

O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [speedTouchstInstall] "C:/Documents and Settings/Paul Holness/Desktop/SetupWizard/stInstall.exe"

O4 - Startup: Karoo.lnk = D:\Start.exe

O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm

O8 - Extra context menu item: Add to AD Black List - C:\Program Files\Avant Browser\AddToADBlackList.htm

O8 - Extra context menu item: Block All Images from the Same Server - C:\Program Files\Avant Browser\AddAllToADBlackList.htm

O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm

O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O8 - Extra context menu item: Highlight - C:\Program Files\Avant Browser\Highlight.htm

O8 - Extra context menu item: Open All Links in This Page... - C:\Program Files\Avant Browser\OpenAllLinks.htm

O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm

O8 - Extra context menu item: Search - C:\Program Files\Avant Browser\Search.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O17 - HKLM\System\CCS\Services\Tcpip\..\{2F1876E1-25BE-4089-9173-4933F8F30001}: NameServer = 212.50.160.100 213.249.130.100

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~2\msgrapp.dll" (file missing)

O21 - SSODL: ShellFolder for CD Burning - {E61B5E20-DE35-11CF-9C87-1579005127ED} - (no file)

O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: iPod Service (iPodService) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)

O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe

O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe

O23 - Service: SmartLinkService (SLService) - Unknown owner - slserv.exe (file missing)

Link to comment
Share on other sites

OK, it is almost clean. This was in your old log: -

 

O21 - SSODL: WebCheck - {E61B5E20-DE35-11CF-9C87-1579005127ED} - (no file)

 

Now this has appeared in the most recent: -

 

O21 - SSODL: ShellFolder for CD Burning - {E61B5E20-DE35-11CF-9C87-1579005127ED} - (no file)

 

As you can see by the long number in brackets, it's the same file, but under a different name. It's related to a toolbar. I dunno what's causing it to come back, but it says (no file) next to it, so you could probably just ignore it.

 

Get on a file sharing service or torrent and download Sygate Firewall. Once you've got that installed you'll be much more protected. Also, go and do your Windows Updates and install Service Pack 2. I've been using a combination of Kaspersky and Sygate and I've not had a virus, spyware infection or anything bad since installing them.

 

You might also want to disable System Restore, reboot, then re-enable it again and create a nice fresh restore point in case anything goes pear-shaped in the near future.

Link to comment
Share on other sites

OK, it is almost clean. This was in your old log: -

 

O21 - SSODL: WebCheck - {E61B5E20-DE35-11CF-9C87-1579005127ED} - (no file)

 

Now this has appeared in the most recent: -

 

O21 - SSODL: ShellFolder for CD Burning - {E61B5E20-DE35-11CF-9C87-1579005127ED} - (no file)

 

As you can see by the long number in brackets, it's the same file, but under a different name. It's related to a toolbar. I dunno what's causing it to come back, but it says (no file) next to it, so you could probably just ignore it.

 

Get on a file sharing service or torrent and download Sygate Firewall. Once you've got that installed you'll be much more protected. Also, go and do your Windows Updates and install Service Pack 2. I've been using a combination of Kaspersky and Sygate and I've not had a virus, spyware infection or anything bad since installing them.

 

You might also want to disable System Restore, reboot, then re-enable it again and create a nice fresh restore point in case anything goes pear-shaped in the near future.

 

Cheers for everything

i'll sort that out right away

Link to comment
Share on other sites

Logfile of HijackThis v1.99.0

Scan saved at 14:38:19, on 23.02.2006

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\SYSTEM32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\PavProt.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\drivers\CDAC11BA.EXE

C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\PaSSrv.exe

C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\Firewall\PavFires.exe

C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\PavFnSvr.exe

C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\Pavkre.exe

C:\Programme\Gemeinsame Dateien\Panda Software\PavShld\pavprsrv.exe

C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\pavsrv51.exe

C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\AVENGINE.EXE

C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\prevsrv.exe

C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\PsImSvc.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\Explorer.EXE

C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\apvxdwin.exe

C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\SRVLOAD.EXE

C:\WINDOWS\SOUNDMAN.EXE

C:\WINDOWS\system32\DeltTray.exe

C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe

C:\Programme\QuickTime\qttask.exe

C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\WebProxy.exe

C:\WINDOWS\Dit.exe

C:\Programme\Java\j2re1.4.2_06\bin\jusched.exe

C:\Programme\iTunes\iTunesHelper.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programme\Messenger\msmsgs.exe

C:\Programme\T-Online\WLAN-Access Finder\ToWLaAcF.exe

C:\Programme\FRITZ!\IWatch.exe

C:\Programme\DT\Sinus 1054 data\Wifiusb.exe

C:\Programme\iPod\bin\iPodService.exe

C:\Programme\Gemeinsame Dateien\Marmiko Shared\MWLaMaS.exe

C:\WINDOWS\System32\wbem\wmiprvse.exe

C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\PAVJOBS.EXE

C:\Programme\meine programme\sicherheitsprogramme\installers\hijackthis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/

O2 - BHO: (no name) - {02DCA195-602B-4B1F-83FF-381B7E804BDB} - C:\WINDOWS\system32\HDBHO.dll

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [DeltTray] DeltTray.exe

O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [Dit] Dit.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Programme\Java\j2re1.4.2_06\bin\jusched.exe

O4 - HKLM\..\Run: [iTunesHelper] C:\Programme\iTunes\iTunesHelper.exe

O4 - HKLM\..\Run: [sCANINICIO] "C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\Inicio.exe"

O4 - HKLM\..\Run: [APVXDWIN] "C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\APVXDWIN.EXE" /s

O4 - HKLM\..\RunServices: [PANDA ANTISPAM SERVER SERVICE] "C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\PasSrv.exe"

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [T-Online_Software_5\WLAN-Access Finder] C:\Programme\T-Online\WLAN-Access Finder\ToWLaAcF.exe /StartMinimized

O4 - HKCU\..\Run: [skype] "C:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - Global Startup: ISDNWatch.lnk = C:\Programme\FRITZ!\IWatch.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE

O4 - Global Startup: Sinus 1054 data WLAN Manager.lnk = ?

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll

O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1108728044261

O17 - HKLM\System\CCS\Services\Tcpip\..\{8A164755-0570-4BF8-A053-4E46784C1B56}: NameServer = 192.168.120.252,192.168.120.253

O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE

O23 - Service: AVM FRITZ!web Routing Service - AVM Berlin - C:\Programme\Gemeinsame Dateien\AVM\de_serv.exe

O23 - Service: iPodService - Apple Computer, Inc. - C:\Programme\iPod\bin\iPodService.exe

O23 - Service: Panda Antispam Server Service - Unknown - C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\PaSSrv.exe

O23 - Service: Panda Firewall Service - Unknown - C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\Firewall\PavFires.exe

O23 - Service: Panda Function Service - Unknown - C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\PavFnSvr.exe

O23 - Service: Panda Pavkre - Unknown - C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\Pavkre.exe

O23 - Service: Panda PavProt - Unknown - C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\PavProt.exe

O23 - Service: Panda Process Protection Service - Unknown - C:\Programme\Gemeinsame Dateien\Panda Software\PavShld\pavprsrv.exe

O23 - Service: Panda anti-virus service - Unknown - C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\pavsrv51.exe

O23 - Service: Panda Preventium+ Service - Unknown - C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\prevsrv.exe

O23 - Service: Panda IManager Service - Panda Software Internacional - C:\Programme\Panda Software\Panda Platinum 2005 Internet Security\PsImSvc.exe

 

any suggestions?

Link to comment
Share on other sites

I'll break down each item you can remove and then you can pick which ones to get rid of: -

 

If you want to get rid of the HiDownload toolbar/browser helper object then fix this item: -

 

O2 - BHO: (no name) - {02DCA195-602B-4B1F-83FF-381B7E804BDB} - C:\WINDOWS\system32\HDBHO.dll

 

Unnecessary Nero app - not required for Nero to function: -

 

O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe

 

Updater for RealPlayer. Not required: -

 

O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot

 

File that makes Quicktime start a little faster when needed. Not required: -

 

O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime

 

Updater for Sun's Java. Not required and also it doesn't work (as can be seen by the old version you're using.): -

 

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Programme\Java\j2re1.4.2_06\bin\jusched.exe

 

Element of Microsoft Office that runs constantly. Go HERE for instructions on how to disable it as fixing it just in HijackThis won't work. Not required for the main Office applications to run: -

 

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

 

MSN Messenger. Can be started from a shortcut when required: -

 

O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background

 

Skype. Can be started from a shortcut when required: -

 

O4 - HKCU\..\Run: [skype] "C:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized

 

Starts the Microsoft Office toolbar. Not required as elements of Office can be started via the Start Menu or shortcuts: -

 

O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE

 

 

 

You also need to update your installation of Java. Click this link to download the latest version: -

 

http://jdl.sun.com/webapps/download/AutoDL?BundleId=10343

 

Uninstall your current version, reboot, then install this new one. Once you're done, run HijackThis again and fix the following new item that will have appeared: -

 

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Programme\Java\jre1.5.0_06\bin\jusched.exe

 

All of the changes will take effect on the next reboot. I see you're using Panda antivirus. That's responsible for a lot of processes, but it's not a bad program so I'd keep it.

Link to comment
Share on other sites

Yep. Also, HijackThis makes backups as long as you're running it from it's own folder so if you make a mistake or you decide you want to restore an item it's easy enough. What you're basically doing is editing the registry but with an easy interface. Any changes you make will take effect when you restart your computer.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...