Someone look at this HijackThis log, please?
From: Allen (Aly929_at_nospam.net)
Date: 12/09/03
- Next message: Allen: "Re: Someone look at this HijackThis log, please?"
- Previous message: Nomad: "Re: Norton personal firewall."
- Next in thread: Allen: "Re: Someone look at this HijackThis log, please?"
- Reply: Allen: "Re: Someone look at this HijackThis log, please?"
- Reply:(deleted message) Bart Bailey: "Re: Someone look at this HijackThis log, please?"
- Reply: bassbag: "Re: Someone look at this HijackThis log, please?"
- Reply: ss_spa_at_hotmail.com: "Re: Someone look at this HijackThis log, please?"
- Reply: sponge: "Re: Someone look at this HijackThis log, please?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Tue, 09 Dec 2003 14:56:23 GMT
Hello,
Some funny things happenning on my PC with trojans etc.
Could someone look at the following HijackThis log and tell me which
of the lines I can "fix"? Thank you kindly for your help.
Actually, I already fixed a lot of lines that looks obviously bogus,
but now my windows 98 start menu bar isn't working... So here is the
latest scan result:
Allen
Logfile of HijackThis v1.95.1
Scan saved at 14:48:44, on 09/12/03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\ANTIVIRUS\AVG\AVGSERV9.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\ATIPTAXX.EXE
C:\SCROLLMOUSE\AWMMAIN.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\ANTIVIRUS\AVG\AVGCC32.EXE
D:\WINUTILS\CD-RW\CLONECD\CLONECDTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\IEDRIVER\IEDRIVER.EXE
C:\PROGRAM FILES\SAVE\SAVE.EXE
C:\WINDOWS\APPLICATION DATA\XPIALYLL.EXE
C:\PROGRAM FILES\COMMONNAME\ADDRESSBAR\WINNET.EXE
D:\WINUTILS\CAPSWARN\CAPHK.EXE
C:\PROGRAM FILES\CLOCKSYNC\SYNC.EXE
F:\SMALLPROGS\12GHOSTSQ\12QUICK.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\TEMP\OBY5281.TMP
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\COMMONNAME\ADDRESSBAR\COMWIZ.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\TEMP\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
file://C:\WINDOWS\SYSTEM\sb.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://wabu.com/passthrough/index.html?http://about:blank
N1 - Netscape 4: user_pref("browser.startup.homepage",
"http://home.netscape.com/"); (C:\Program
Files\Netscape\Users\default\prefs.js)
N3 - Netscape 7: user_pref("browser.startup.homepage",
"http://home.netscape.com/"); (C:\WINDOWS\Application
Data\Mozilla\Profiles\default\btqke1mp.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine",
"http://www.google.com/"); (C:\WINDOWS\Application
Data\Mozilla\Profiles\default\btqke1mp.slt\prefs.js)
O2 - BHO: (no name) - {6ba6a620-2a55-11d8-b0ea-0004e285b36a} -
C:\WINDOWS\APPLICATION DATA\KCKSHCHOUOEE.DLL
O3 - Toolbar: ealylyjbrho - {6ba6a621-2a55-11d8-b0ea-0004e285b36a} -
C:\WINDOWS\APPLICATION DATA\KCKSHCHOUOEE.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
O4 - HKLM\..\Run: [AtiQiPcl] AtiQiPcl.exe
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [WheelMouse] C:\Scrollmouse\AWMMAIN.EXE
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [W3KNetwork] RunDll32.exe w3knet.dll,DLLInitRun
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SpyStopper] D:\WINUTILS\SPYSTOPPER\spystopper.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program
Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe]
C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE"
-atboottime
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\Run: [sysPnP] C:\WINDOWS\SYSTEM\bootconf.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\ANTIVI~1\AVG\avgcc32.exe
/STARTUP
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\NETSEC~1\SYGATE~1\SMC.EXE
-startgui
O4 - HKLM\..\Run: [CloneCDTray]
"D:\WINUTILS\CD-RW\CloneCD\CloneCDTray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [IEDriver] C:\WINDOWS\SYSTEM\IEDriver\IEDriver.exe
O4 - HKLM\..\Run: [WhenUSave] C:\Program Files\Save\Save.exe
O4 - HKLM\..\Run: [llouock] C:\WINDOWS\APPLIC~1\xpialyll.exe -QuieT
O4 - HKLM\..\Run: [winnet] C:\PROGRA~1\COMMON~2\ADDRES~1\WINNET.EXE
O4 - HKLM\..\RunServices: [ATIPOLAB] ati2evxx.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [Avgserv9.exe]
C:\PROGRA~1\ANTIVI~1\AVG\Avgserv9.exe
O4 - HKCU\..\Run: [FirstCap] D:\WINUTILS\capswarn\CapHk.exe
O4 - HKCU\..\Run: [TClockEx] D:\WINUTILS\TCLOCKEX\TCLOCKEX.EXE
O4 - HKCU\..\Run: [IM] D:\WINUTILS\INSTANT MESSENGER\aim.exe
-cnetwait.odl
O4 - HKCU\..\Run: [ClockSync] C:\Program Files\ClockSync\Sync.exe /q
O4 - Startup: 12quick.lnk = F:\Smallprogs\12ghostsQ\12quick.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions
present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel
present
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O11 - Options group: [CommonName] CommonName
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash
Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX
Control) -
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37826.2640972222
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI
Registry Information Class) -
http://security.symantec.com/SSC/SharedContent/common/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus
scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O19 - User style***: C:\WINDOWS\default.css
- Next message: Allen: "Re: Someone look at this HijackThis log, please?"
- Previous message: Nomad: "Re: Norton personal firewall."
- Next in thread: Allen: "Re: Someone look at this HijackThis log, please?"
- Reply: Allen: "Re: Someone look at this HijackThis log, please?"
- Reply:(deleted message) Bart Bailey: "Re: Someone look at this HijackThis log, please?"
- Reply: bassbag: "Re: Someone look at this HijackThis log, please?"
- Reply: ss_spa_at_hotmail.com: "Re: Someone look at this HijackThis log, please?"
- Reply: sponge: "Re: Someone look at this HijackThis log, please?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]