There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
 
Virus & Other Malware Removal
Tag Cloud
access backup bios blue screen boot bsod connection crash dell dns drivers error firefox freeze freezing graphics card hard drive hardware html install internet internet explorer itunes laptop malware mcafee memory motherboard mouse network problem ram registry router spyware startup system restore toshiba trojan usb video virus vista website windows windows 7 windows 7 32-bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > Virus & Other Malware Removal >
Please help with hijackthis log file (New)

Closed Thread
 
Thread Tools
tnpuddleduck's Avatar
Member with 44 posts.
 
Join Date: Oct 2003
30-Oct-2003, 09:17 AM #1
Please help with hijackthis log file
Thanks in advance for help guys, here is my log file, one question my explorer start page has this ehttp.cc\? before my home page. How do I fix, and if there are any other problems you see, let me know. Thanks again
Logfile of HijackThis v1.97.2
Scan saved at 8:00:06 AM, on 10/30/03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\AVSYNMGR.EXE
C:\PROGRAM FILES\NORTON CLEANSWEEP\CSINJECT.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSSTAT.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSHWIN32.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\AVCONSOL.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\WEBSCANX.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\TASKMON.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\EVNTSVC.EXE
C:\PROGRAM FILES\NORTON CLEANSWEEP\CSINSM32.EXE
C:\Program Files\Norton CleanSweep\Monwow.exe
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\ANALOGX\POW\POW.EXE
C:\PROGRAM FILES\ZIPCENTRAL\ZCENTRAL.EXE
C:\WINDOWS\TEMP\_ZCTMP.DIR\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ehttp.cc/?www.netscape.com
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.netscape.com/"); (c:\Program Files\Netscape\Users\bgallway\prefs.js)
O1 - Hosts: 66.118.163.109 auto.search.msn.com
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Mount Safe & Sound] C:\PROGRAM FILES\MCAFEE\MCAFEE SHARED COMPONENTS\SAFE & SOUND\FBMOUNT.EXE
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AvconsoleEXE] C:\Program Files\Network Associates\McAfee VirusScan\avconsol.exe /minimize
O4 - HKLM\..\Run: [VsStatEXE] C:\Program Files\Network Associates\McAfee VirusScan\VSSTAT.EXE /SHOWWARNING
O4 - HKLM\..\Run: [VsEcomrEXE] C:\Program Files\Network Associates\McAfee VirusScan\vsecomr.exe
O4 - HKLM\..\Run: [McAfeeWebScanX] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\WebScanX.Exe
O4 - HKLM\..\Run: [Vshwin32EXE] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
O4 - HKLM\..\Run: [C:\WINDOWS\SYSTEM\gone.scr] C:\WINDOWS\SYSTEM\gone.scr
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\RunServices: [McAfeeVirusScanService] c:\Program Files\McAfee\McAfee VirusScan\AVSYNMGR.EXE
O4 - HKLM\..\RunServices: [CSINJECT.EXE] C:\Program Files\Norton CleanSweep\CSINJECT.EXE
O4 - HKCU\..\Run: [AddClass] C:\WINDOWS\ADDCLASS.EXE
O4 - Startup: CleanSweep Smart Sweep-Internet Sweep.lnk = C:\Program Files\Norton CleanSweep\csinsm32.exe
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Dell Home (HKCU)
O13 - DefaultPrefix: http://ehttp.cc/?
O13 - WWW Prefix: http://ehttp.cc/?
O16 - DPF: ChatSpace JavaLight Client - http://64.85.20.108:8058/Java/cslt4.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab
O16 - DPF: {525A15D0-4938-11D4-94C7-0050DA20189B} (SnoopyCtrl Class) - http://netcenter.ea.com/downloads/ga...y/iesnoopy.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...868.2200462963
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) - http://a840.g.akamai.net/7/840/5805/...ditControl.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.0_01) -
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -
e-liam's Avatar
Senior Member with 1,256 posts.
 
Join Date: Jun 2003
Location: Bracknell - UK
Experience: Advanced
30-Oct-2003, 09:45 AM #2
Hi tnpuddleduck, and welcome to TSG..

Please run a new HJT! Scan, and check to fix the following entries. Next, close all browser windows and click the Fix checked button…

O1 - Hosts: 66.118.163.109 auto.search.msn.com

O4 - HKLM\..\Run: [C:\WINDOWS\SYSTEM\gone.scr] C:\WINDOWS\SYSTEM\gone.scr

O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot

O13 - DefaultPrefix: http://ehttp.cc/?

O13 - WWW Prefix: http://ehttp.cc/?

O16 - DPF: {525A15D0-4938-11D4-94C7-0050DA20189B} (SnoopyCtrl Class) - http://netcenter.ea.com/downloads/g...py/iesnoopy.cab

O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab

O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) - http://a840.g.akamai.net/7/840/5805...uditControl.cab


Then please serch for and delete the following bolded file..

C:\WINDOWS\SYSTEM\gone.scr

Then could you go here and run the online virus scan. Delete all it finds.

Then please reboot and download Spybot - Search & Destroy, from here: if you haven't already got the program.

Now press Settings, and Settings again. Go to the Webupdate section, and check "Display also available beta versions".

Now press Online, and search for, put a check mark at, and install all updates.

Next, close all Internet Explorer windows, hit 'Check for Problems', and have SpyBot remove all it finds marked RED.

After that, please reboot and post a new log.

Cheers

Liam
__________________
"You cannot reason someone out of a position that they did not reason themselves into in the first place." Anon

Give a man a fish, and he may eat for a day;
but teach a man to fish, and he can sit in a boat all day, drinking beer.

A proud member of the Alliance of Security Analysis Professionals since 2004.
tnpuddleduck's Avatar
Member with 44 posts.
 
Join Date: Oct 2003
30-Oct-2003, 12:26 PM #3
Thanks for help Liam
I tried to run scan from online source you gave, downloaded it but it would not scan. I can not find how to select settings with Spybot. I have this program and keep it up to date, however the "settings" tab does not seem to be available to me. Perhaps it needs to be loaded different?
Here is my latest Hijackthis, Thanks again for your assistance
Logfile of HijackThis v1.97.2
Scan saved at 11:24:15 AM, on 10/30/03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\AVSYNMGR.EXE
C:\PROGRAM FILES\NORTON CLEANSWEEP\CSINJECT.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSSTAT.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSHWIN32.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\AVCONSOL.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\WEBSCANX.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\TASKMON.EXE
C:\PROGRAM FILES\NORTON CLEANSWEEP\CSINSM32.EXE
C:\Program Files\Norton CleanSweep\Monwow.exe
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\ANALOGX\POW\POW.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\ZIPCENTRAL\ZCENTRAL.EXE
C:\WINDOWS\TEMP\_ZCTMP.DIR\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netscape.com/
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.netscape.com/"); (c:\Program Files\Netscape\Users\bgallway\prefs.js)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Mount Safe & Sound] C:\PROGRAM FILES\MCAFEE\MCAFEE SHARED COMPONENTS\SAFE & SOUND\FBMOUNT.EXE
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AvconsoleEXE] C:\Program Files\Network Associates\McAfee VirusScan\avconsol.exe /minimize
O4 - HKLM\..\Run: [VsStatEXE] C:\Program Files\Network Associates\McAfee VirusScan\VSSTAT.EXE /SHOWWARNING
O4 - HKLM\..\Run: [VsEcomrEXE] C:\Program Files\Network Associates\McAfee VirusScan\vsecomr.exe
O4 - HKLM\..\Run: [McAfeeWebScanX] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\WebScanX.Exe
O4 - HKLM\..\Run: [Vshwin32EXE] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
O4 - HKLM\..\RunServices: [McAfeeVirusScanService] c:\Program Files\McAfee\McAfee VirusScan\AVSYNMGR.EXE
O4 - HKLM\..\RunServices: [CSINJECT.EXE] C:\Program Files\Norton CleanSweep\CSINJECT.EXE
O4 - HKCU\..\Run: [AddClass] C:\WINDOWS\ADDCLASS.EXE
O4 - HKCU\..\RunServices: [AddClass] C:\WINDOWS\ADDCLASS.EXE
O4 - Startup: CleanSweep Smart Sweep-Internet Sweep.lnk = C:\Program Files\Norton CleanSweep\csinsm32.exe
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Dell Home (HKCU)
O16 - DPF: ChatSpace JavaLight Client - http://64.85.20.108:8058/Java/cslt4.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...868.2200462963
O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) - http://a840.g.akamai.net/7/840/5805/...ditControl.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.0_01) -
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/d...ll/xscan53.cab
$teve's Avatar
Distinguished Member with 9,520 posts.
 
Join Date: Oct 2001
Location: 25 miles from Manchester/Engla
Experience: Tweedle-Dee
30-Oct-2003, 01:10 PM #4
Its a clean log now

In the main spybot windows the settings button is on the left....hit that and you will see the 2nd settings button.

e-liam's Avatar
Senior Member with 1,256 posts.
 
Join Date: Jun 2003
Location: Bracknell - UK
Experience: Advanced
30-Oct-2003, 01:18 PM #5
Hi, tnpuddleduck,

As far as Spybot is concerned, that explanation is for first time users. If you already have it and keep it upto date, then your fine just running it as stated.

With the virus scan, it's actually done online, with you downloading the activex control, first. You've now got that, as can be seen in the last entry in your new log.

The reason for doing this scan is that the gone.scr entry is a virus. See here for info. Running a scan with Housecall will make sure that, although it doesn't show in the log now, all references to it are deleted.

Could you please go back to that page I gave the link to, select the country you're in, then press the Go button. Then on the next page shown, just click the Scan Now button (as shown in the attached image).

Apart from that you have a clean log...

Cheers

Liam
Attachment Blocked
Attachments in the HJT forum are often designed to solve a specific issue and not meant to be used without instructions specific to your computer. If you want help specific to your computer, please post a HiJackThis Log. If you started this thread, please make sure you are logged in to be able to view attachments.
__________________
"You cannot reason someone out of a position that they did not reason themselves into in the first place." Anon

Give a man a fish, and he may eat for a day;
but teach a man to fish, and he can sit in a boat all day, drinking beer.

A proud member of the Alliance of Security Analysis Professionals since 2004.
e-liam's Avatar
Senior Member with 1,256 posts.
 
Join Date: Jun 2003
Location: Bracknell - UK
Experience: Advanced
30-Oct-2003, 01:21 PM #6
We'll have to stop meeting like this, Steve... people will talk..
TomCoyote's Avatar
Junior Member with 1 posts.
 
Join Date: May 2003
10-Nov-2003, 11:14 AM #7
YOu need a new HJT download
Your post indicates another baddie missed and is the culprit of the default prefixes

O4 - HKCU\..\Run: [AddClass] C:\WINDOWS\ADDCLASS.EXE


However your HJT needs to be updated to the current version

http://TomCoyote.org/hjt/

Please do that first
$teve's Avatar
Distinguished Member with 9,520 posts.
 
Join Date: Oct 2001
Location: 25 miles from Manchester/Engla
Experience: Tweedle-Dee
10-Nov-2003, 01:23 PM #8
Thanx Tom........Stands out like a sore thumb and im embarressed to have missed that one.
I must get some glasses just like yours

scarlettsilk's Avatar
Member with 41 posts.
 
Join Date: Nov 2003
13-Nov-2003, 07:05 AM #9
can i just delete the addclass.exe file? neither my virus scanner, housecall or spybot have removed it. also it is saying that the bkdr lixy virus in my ssocks32.dll and msm32.dll cannot be removed....so how do i get the infected files out?
Metallica's Avatar
Senior Member with 692 posts.
 
Join Date: Jan 2003
13-Nov-2003, 07:09 AM #10
Hi scarlettsilk,

Please post your log in your own thread, and we will take it from there:
http://forums.techguy.org/t179256/s.html

Regards,

Pieter

PS Hi TomCoyote
fkrl's Avatar
Junior Member with 3 posts.
 
Join Date: Jun 2004
07-Jun-2004, 12:27 PM #11
The Default Prefix is located in the registry under 'HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ URL \ DefaultPrefix \'.

Reset the Default Prefix manually
To reset the Default Prefix settings, follow the instructions below, which includes minor modifications to the registry.

Start the registry editor. This is done by clicking Start then Run. (The Run dialog will appear.) Type regedit and click OK. (The registry editor will open.)
Browse to the key:
'HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ URL \ DefaultPrefix \'.
In the right pane, right-click the '(Default)' value and modify its data to 'http://'
Exit the registry editor.
Close all Internet Explorer browsers.
Your browser should now have the default WWW prefix, and you can verify this by entering 'kephyr.com' in the Internet Explorer address field. The domain name should be replaced with the http://kephyr.com/ URL.
posted on 2004年06月08日 12:22 AM
~Candy~'s Avatar
Former Administrator with 104,745 posts.
 
Join Date: Jan 2001
Experience: Advanced
07-Jun-2004, 01:29 PM #12
This thread is 6 months old

And what is so special about kephyr.com?
cybertech's Avatar
Computer Specs
Moderator with 69,099 posts.
 
Join Date: Apr 2002
Location: Washington State
07-Jun-2004, 01:29 PM #13
fkrl,
Welcome to TSG!!

The tread you posted in here is pretty old Are you asking for help or just making a comment?
cybertech's Avatar
Computer Specs
Moderator with 69,099 posts.
 
Join Date: Apr 2002
Location: Washington State
07-Jun-2004, 01:29 PM #14
Candy's got faster reaction time today
FinestRanger's Avatar
Distinguished Member with 2,387 posts.
 
Join Date: Oct 2003
Location: Northern Minnesota
08-Jul-2004, 09:42 PM #15
I'm going to request that your thread's separated from this one. Attaching a new thread to an old one's a REALLY REALLY bad idea...you'll often get overlooked. No big deal, it's for your benefit.
Closed Thread

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.

Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 11:13 PM.
Copyright © 1996 - 2010 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.