| Live Chat & Podcast at 1:00PM Eastern on Sunday! |
| | |
| Thread Tools |
|
08-Aug-2004, 01:23 PM
#1 |
| Computer restarting, serious errors + much more - hijack this log included hi, I have another thread in windows xp forum but it has been suggested to me that I might get more luck here posting my hijack this log. BAsically the computer started restarting itself with serious error messages referring to Ntfs.sys file. Gradually the problems have got worse and now I cannot access many windows things. The icons in control panel do not work and search and run in the start menu have become unclickable. Basically all the problems I have encountered are in this thread : http://forums.techguy.org/showthread...=1#post1840970 This is my hijack this log: Logfile of HijackThis v1.95.0 Scan saved at 17:22:28, on 08/08/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Norton Internet Security\NISUM.EXE C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe C:\Program Files\Tiny Personal Firewall\persfw.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Panda Software\Panda Antivirus Titanium\AVENGINE.EXE C:\WINDOWS\soundman.exe C:\Program Files\ahead\InCD\InCD.exe C:\WINDOWS\System32\sistray.EXE C:\WINDOWS\System32\khooker.exe C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\Creative\Shared Files\CAMTRAY.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Norton Internet Security\ccPxySvc.exe C:\WINDOWS\System32\ctfmon.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe C:\Program Files\Panda Software\Panda Antivirus Titanium\pavProxy.exe C:\Program Files\Tesconet\Tesconet.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Windows NT\Accessories\wordpad.exe C:\downloads\Antivirus\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page=res://mshp.dll/sp.html#22776 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.tesco.net/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page=res://mshp.dll/index.html#22776 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page=res://mshp.dll/sp.html#22776 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL=res://mshp.dll/index.html#22776 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL=res://mshp.dll/sp.html#22776 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page=http://www.tesco.net R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\System32\blank.htm O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Messenger\ycomp.dll O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Surf Pal\CCHelper.dll O2 - BHO: (no name) - {2E9CAFF6-30C7-4208-8807-E79D4EC6F806} - C:\Program Files\Submit\submithook.dll O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing) O2 - BHO: (no name) - {C1E58A84-95B3-4630-B8C2-D06B77B7A0FC} - C:\Program Files\NavExcel\NavHelper\v2.0.4c\NHelper.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Panicware Surf &Pal - {0ADCDFE7-8490-406D-91BF-88F71FD7F8AE} - C:\Program Files\Panicware\Surf Pal\pwicc.dll O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Messenger\ycomp.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing) O4 - HKLM\..\Run: [SoundMan] soundman.exe O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe" O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE" /s O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE O4 - HKLM\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet O4 - Startup: Gangsters2Setup.lnk = ? O4 - Startup: PowerReg SchedulerV2.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: Download &All by FD - fdiectx2.htm O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm O8 - Extra context menu item: Download with &FD - fdiectx.htm O9 - Extra button: Real.com (HKLM) O9 - Extra button: FlashGet (HKLM) O9 - Extra 'Tools' menuitem: &FlashGet (HKLM) O9 - Extra button: Yahoo! Messenger (HKLM) O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM) O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://www.tesco.net O16 - DPF: ChatSpace Full Java Client 3.1.0.229 - http://chat-a3.freeserve.com/Java/cfs31229.cab O16 - DPF: ChatSpace Full Java Client 4.0.0.300 - http://about.chatspace.com/Java/cfs40300.cab O16 - DPF: NTLSignup - https://tesco.autoregister.net/tesco/NTLSignup.cab O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab O16 - DPF: Yahoo! Chat 1.3 - http://cs8.chat.sc5.yahoo.com/c174/chat.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...205.5336574074 O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.com/security/co...20/SassCln.CAB O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab Please would someone be able to help me as I don't really have much of an idea as to what I am doing |
| |
08-Aug-2004, 01:52 PM
#2 | |||||
| The version of Hijack This you have is very old so get rid of the old one and Click here to download the new one, come back here and post the log from it. |
|
08-Aug-2004, 02:27 PM
#3 |
| OK thanks here is the newer version, also I keep trying online virus scanners and they just keep disappearing/closing themselves while the scan is going on. Some become unclickable and I download some free/trial ones and they do download but when I click on them to install them they just disappear. Anyway heres the new version hijack this log Logfile of HijackThis v1.98.2 Scan saved at 18:23:01, on 08/08/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Norton Internet Security\NISUM.EXE C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe C:\Program Files\Tiny Personal Firewall\persfw.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Panda Software\Panda Antivirus Titanium\AVENGINE.EXE C:\WINDOWS\soundman.exe C:\Program Files\ahead\InCD\InCD.exe C:\WINDOWS\System32\sistray.EXE C:\WINDOWS\System32\khooker.exe C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\Creative\Shared Files\CAMTRAY.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Norton Internet Security\ccPxySvc.exe C:\WINDOWS\System32\ctfmon.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe C:\Program Files\Panda Software\Panda Antivirus Titanium\pavProxy.exe C:\Program Files\Windows NT\Accessories\wordpad.exe C:\downloads\Antivirus\HijackThis.exe C:\WINDOWS\notepad.exe C:\Program Files\FlashGet\flashget.exe C:\Program Files\Tesconet\Tesconet.exe C:\Program Files\Internet Explorer\iexplore.exe C:\downloads\hijackthis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://mshp.dll/sp.html#22776 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tesco.net/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://mshp.dll/index.html#22776 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://mshp.dll/sp.html#22776 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://mshp.dll/sp.html#22776 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://mshp.dll/index.html#22776 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.tesco.net O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Messenger\ycomp.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: CCHelper Class - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Surf Pal\CCHelper.dll O2 - BHO: (no name) - {2E9CAFF6-30C7-4208-8807-E79D4EC6F806} - C:\Program Files\Submit\submithook.dll O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing) O2 - BHO: NavHelper Class - {C1E58A84-95B3-4630-B8C2-D06B77B7A0FC} - C:\Program Files\NavExcel\NavHelper\v2.0.4c\NHelper.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Panicware Surf &Pal - {0ADCDFE7-8490-406D-91BF-88F71FD7F8AE} - C:\Program Files\Panicware\Surf Pal\pwicc.dll O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Messenger\ycomp.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing) O4 - HKLM\..\Run: [SoundMan] soundman.exe O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe" O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE" /s O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE O4 - HKLM\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet O4 - Startup: Gangsters2Setup.lnk = ? O4 - Startup: PowerReg SchedulerV2.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: Download &All by FD - fdiectx2.htm O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm O8 - Extra context menu item: Download with &FD - fdiectx.htm O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://www.tesco.net O15 - Trusted Zone: http://register-tesco.qa.business.ntl.com O15 - Trusted Zone: http://memberservices.tesco.net O16 - DPF: ChatSpace Full Java Client 3.1.0.229 - http://chat-a3.freeserve.com/Java/cfs31229.cab O16 - DPF: ChatSpace Full Java Client 4.0.0.300 - http://about.chatspace.com/Java/cfs40300.cab O16 - DPF: NTLSignup - https://tesco.autoregister.net/tesco/NTLSignup.cab O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab O16 - DPF: Yahoo! Chat 1.3 - http://cs8.chat.sc5.yahoo.com/c174/chat.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{D2B53267-BD24-48F0-9BCC-8FB5F987D7D8}: NameServer = 194.168.4.100 194.168.8.100 |
08-Aug-2004, 03:05 PM
#4 | |||||
| You have a CWS hijack that is difficult to remove,. This hijacker installs a rogue service on your machine so we need to get the name of that service before we proceed with the removal. Download the attached zip file and unzip it to your desktop. Doubleclick to run it. It will get a list of active services. Please post the list that is generated.
__________________ If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site. |
|
08-Aug-2004, 03:20 PM
#5 |
| Thank you very much for your reply flrman1 I actually feel I am getting somewhere. Unfortunately I am getting this message when I try to open the unzipped file: Can't find script engine "VBScript" for script "C:\Documents and Settings\My Name\Desktop\get active services.vbs". What should I do now? Thanks again - really apprieciated |
08-Aug-2004, 03:37 PM
#6 | |||||
| Try reinstalling Microsoft scripting from here: http://msdn.microsoft.com/library/de...ist/webdev.asp Then run the script again. |
|
08-Aug-2004, 04:01 PM
#7 |
| OK, thanks, I done that and it told me to restart my computer to complete installation. I did that and then clicked the get active services icon on my computer and got first a message box in the heading was: C:\programfiles\tinypersonalfirewall\persfw.exe and the message underneath it said Service_Control_Interrogate Then a couple of seconds later I had the following message box: -------------------------------------- Windows Script Host Script: C:\Documents and Settings\my name\desktop\get active services.vbs Line: 19 Char: 5 Error: The remote procedure call failed Code: 800706BE Source: (null) --------------------------------------- Then it wouldn't allow me to connect to the internet so I restarted my computer, the internet worked then. Is this what you were looking for? What do I do now? Thanks again flrman1 |
|
08-Aug-2004, 04:37 PM
#8 |
| OK, sorry about the above flrman1, after some thinking I thought that maybe the tiny personal is stopping me get the info. So I just uninstalled. Here is the active services These are the Current Active Services: ALERTER: Alerter C:\WINDOWS\System32\svchost.exe -k LocalService TCP/IP NETBIOS HELPER: LmHosts C:\WINDOWS\System32\svchost.exe -k LocalService REMOTE REGISTRY: RemoteRegistry C:\WINDOWS\system32\svchost.exe -k LocalService SSDP DISCOVERY SERVICE: SSDPSRV C:\WINDOWS\System32\svchost.exe -k LocalService WEBCLIENT: WebClient C:\WINDOWS\System32\svchost.exe -k LocalService APPLICATION LAYER GATEWAY SERVICE: ALG C:\WINDOWS\System32\alg.exe WINDOWS AUDIO: AudioSrv C:\WINDOWS\System32\svchost.exe -k netsvcs COMPUTER BROWSER: Browser C:\WINDOWS\System32\svchost.exe -k netsvcs CRYPTOGRAPHIC SERVICES: CryptSvc C:\WINDOWS\system32\svchost.exe -k netsvcs DHCP CLIENT: Dhcp C:\WINDOWS\System32\svchost.exe -k netsvcs LOGICAL DISK MANAGER: dmserver C:\WINDOWS\System32\svchost.exe -k netsvcs ERROR REPORTING SERVICE: ERSvc C:\WINDOWS\System32\svchost.exe -k netsvcs COM+ EVENT SYSTEM: EventSystem C:\WINDOWS\System32\svchost.exe -k netsvcs FAST USER SWITCHING COMPATIBILITY: FastUserSwitchingCompatibility C:\WINDOWS\System32\svchost.exe -k netsvcs HELP AND SUPPORT: helpsvc C:\WINDOWS\System32\svchost.exe -k netsvcs SERVER: lanmanserver C:\WINDOWS\System32\svchost.exe -k netsvcs WORKSTATION: lanmanworkstation C:\WINDOWS\System32\svchost.exe -k netsvcs NETWORK CONNECTIONS: Netman C:\WINDOWS\System32\svchost.exe -k netsvcs NETWORK LOCATION AWARENESS (NLA): Nla C:\WINDOWS\System32\svchost.exe -k netsvcs REMOTE ACCESS CONNECTION MANAGER: RasMan C:\WINDOWS\System32\svchost.exe -k netsvcs TASK SCHEDULER: Schedule C:\WINDOWS\System32\svchost.exe -k netsvcs SECONDARY LOGON: seclogon C:\WINDOWS\System32\svchost.exe -k netsvcs SYSTEM EVENT NOTIFICATION: SENS C:\WINDOWS\system32\svchost.exe -k netsvcs INTERNET CONNECTION FIREWALL (ICF) / INTERNET CONNECTION SHARING (ICS): SharedAccess C:\WINDOWS\System32\svchost.exe -k netsvcs SHELL HARDWARE DETECTION: ShellHWDetection C:\WINDOWS\System32\svchost.exe -k netsvcs SYSTEM RESTORE SERVICE: srservice C:\WINDOWS\System32\svchost.exe -k netsvcs TELEPHONY: TapiSrv C:\WINDOWS\System32\svchost.exe -k netsvcs TERMINAL SERVICES: TermService C:\WINDOWS\System32\svchost.exe -k netsvcs THEMES: Themes C:\WINDOWS\System32\svchost.exe -k netsvcs DISTRIBUTED LINK TRACKING CLIENT: TrkWks C:\WINDOWS\system32\svchost.exe -k netsvcs UPLOAD MANAGER: uploadmgr C:\WINDOWS\System32\svchost.exe -k netsvcs WINDOWS TIME: W32Time C:\WINDOWS\System32\svchost.exe -k netsvcs WINDOWS MANAGEMENT INSTRUMENTATION: winmgmt C:\WINDOWS\system32\svchost.exe -k netsvcs PORTABLE MEDIA SERIAL NUMBER: WmdmPmSp C:\WINDOWS\System32\svchost.exe -k netsvcs AUTOMATIC UPDATES: wuauserv C:\WINDOWS\system32\svchost.exe -k netsvcs WIRELESS ZERO CONFIGURATION: WZCSVC C:\WINDOWS\System32\svchost.exe -k netsvcs SYMANTEC EVENT MANAGER: ccEvtMgr C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe SYMANTEC PROXY SERVICE: ccPxySvc C:\Program Files\Norton Internet Security\ccPxySvc.exe DNS CLIENT: Dnscache C:\WINDOWS\System32\svchost.exe -k NetworkService EVENT LOG: Eventlog C:\WINDOWS\system32\services.exe PLUG AND PLAY: PlugPlay C:\WINDOWS\system32\services.exe NORTON INTERNET SECURITY ACCOUNTS MANAGER: NISUM C:\Program Files\Norton Internet Security\NISUM.EXE PANDA ANTI-VIRUS SERVICE: PAVSRV C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe IPSEC SERVICES: PolicyAgent C:\WINDOWS\System32\lsass.exe PROTECTED STORAGE: ProtectedStorage C:\WINDOWS\system32\lsass.exe SECURITY ACCOUNTS MANAGER: SamSs C:\WINDOWS\system32\lsass.exe REMOTE PROCEDURE CALL (RPC): RpcSs C:\WINDOWS\system32\svchost -k rpcss PRINT SPOOLER: Spooler C:\WINDOWS\system32\spoolsv.exe WINDOWS IMAGE ACQUISITION (WIA): stisvc C:\WINDOWS\System32\svchost.exe -k imgsvc Thanks |
08-Aug-2004, 07:40 PM
#9 | |||||
| I don't see the service that I'm looking for there, but sometimes the script doesn't find it. Let's try something else. Download the Registry Search Tool here: http://www.billsway.com/vbspage/ Unzip it and run it. If your antivirus inteferes you may have to disable script blocking in the antivirus. Put the following in the search box: O?rtńĺȲ$Ó Copy and paste the results here. Do the same registry search again with this line: ˝O.#őŘ´â Copy and paste the results of both searches here.
__________________ If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site. |
08-Aug-2004, 08:56 PM
#11 | |||||
| There is one thing we can try that works on this one sometimes so let's give it a shot. Click here to download AboutBuster created by Rubber Ducky. Unzip AboutBuster to the Desktop then click the "Update Button" then click "Check for Update" and download the updates and then click "Exit" because I don't want you to run it yet. Just get the updates so it is ready to run later in safe mode. Restart to safe mode. How to start your computer in safe mode In safe mode run aboutbuster. Double click aboutbuster.exe, click OK, click Start, then click OK. This will scan your computer for the bad files and delete them. Boot back to normal and run AboutBuster one more time and restart you computer again and the post a new Hijack This log.
__________________ If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site. |
|
08-Aug-2004, 09:50 PM
#12 |
| Thanks Ok I did as you said but I had a problem: I downloaded Aboutbuster and checked for updates. Then I restarted my computer and turned to safe mode. When I started Aboutbuster for the first time it got to about 9% through and just dissappeared from view as if it had been shut down (like what sometimes happens when I try to use the online virus scanners). So I clicked on it again and it got to 33% through but this time everything just freezed so I had to restart my computer by the button. Then I had a black screen with an exception message on it. So I restarted again and put it back in to safe mode and tried Aboutbuster again - this time it got to 66% before again dissappearing so I clicked on it again and this time it went 100% through, it asked me if I wanted to do a second scan so I pressed 'yes' and this went through to 100% first time. In the Aboutbuster box it said 'attempted clean of temp folder pages reset....done' So I restarted the computer and in normal mode tried to run Aboutbuster but I kept getting it dissappear or the computer freeze on me. I have tried a many times. Where as in safe mode it would get closer to 100% each time I performed a scan in normal mode it sometimes gets to 6% or 9% before eithier freezing or dissappearing. My hijack this log after carrying out the above events is below: Logfile of HijackThis v1.98.2 Scan saved at 01:37:09, on 09/08/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Norton Internet Security\NISUM.EXE C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\soundman.exe C:\Program Files\ahead\InCD\InCD.exe C:\WINDOWS\System32\sistray.EXE C:\Program Files\Panda Software\Panda Antivirus Titanium\AVENGINE.EXE C:\WINDOWS\System32\khooker.exe C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\Creative\Shared Files\CAMTRAY.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\System32\ctfmon.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\Norton Internet Security\ccPxySvc.exe C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe C:\Program Files\Panda Software\Panda Antivirus Titanium\pavProxy.exe C:\Program Files\Tesconet\Tesconet.exe C:\Program Files\Internet Explorer\iexplore.exe C:\downloads\hijackthis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.tesco.net O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Messenger\ycomp.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: CCHelper Class - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Surf Pal\CCHelper.dll O2 - BHO: (no name) - {2E9CAFF6-30C7-4208-8807-E79D4EC6F806} - C:\Program Files\Submit\submithook.dll O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing) O2 - BHO: NavHelper Class - {C1E58A84-95B3-4630-B8C2-D06B77B7A0FC} - C:\Program Files\NavExcel\NavHelper\v2.0.4c\NHelper.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Panicware Surf &Pal - {0ADCDFE7-8490-406D-91BF-88F71FD7F8AE} - C:\Program Files\Panicware\Surf Pal\pwicc.dll O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Messenger\ycomp.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing) O4 - HKLM\..\Run: [SoundMan] soundman.exe O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe" O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE" /s O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE O4 - HKLM\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet O4 - Startup: Gangsters2Setup.lnk = ? O4 - Startup: PowerReg SchedulerV2.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: Download &All by FD - fdiectx2.htm O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm O8 - Extra context menu item: Download with &FD - fdiectx.htm O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://www.tesco.net O15 - Trusted Zone: http://register-tesco.qa.business.ntl.com O15 - Trusted Zone: http://memberservices.tesco.net O16 - DPF: ChatSpace Full Java Client 3.1.0.229 - http://chat-a3.freeserve.com/Java/cfs31229.cab O16 - DPF: ChatSpace Full Java Client 4.0.0.300 - http://about.chatspace.com/Java/cfs40300.cab O16 - DPF: NTLSignup - https://tesco.autoregister.net/tesco/NTLSignup.cab O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab O16 - DPF: Yahoo! Chat 1.3 - http://cs8.chat.sc5.yahoo.com/c174/chat.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{D2B53267-BD24-48F0-9BCC-8FB5F987D7D8}: NameServer = 194.168.4.100 194.168.8.100 What can I do now? Thanks |
09-Aug-2004, 12:07 AM
#13 | |||||
| Run Hijack This again and put a check by these. Close ALL windows except HijackThis and click "Fix checked" O2 - BHO: (no name) - {2E9CAFF6-30C7-4208-8807-E79D4EC6F806} - C:\Program Files\Submit\submithook.dll O4 - Startup: Gangsters2Setup.lnk = ? O4 - Startup: PowerReg SchedulerV2.exe Restart your computer. Go here and do an online virus scan. Be sure and put a check in the box by "Auto Clean" before you do the scan. If it finds anything that it cannot clean have it delete it or make a note of the file location so you can delete it yourself. Housecall will detect the leftover files from this hijacker. This hijacker is known to alter or delete certain files so check this out please: Download the Hoster from here . UnZip the file and press "Restore Original Hosts" and press "OK". Exit Program. If you have Spybot S&D installed you will also need to replace one file. Go here and download SDHelper.dll. Copy the file to the folder containing you Spybot S&D program (normally C:\Program Files\Spybot - Search & Destroy) Check in the System32 folder to be sure you have a file named Shell.dll. If you do not have one, go to System32\dllcache Find shell.dll and right click on it. Choose Copy from the menu. Open System32 and right click on an empty space in the window. Choose Paste from the menu. control.exe may have been deleted. See if control.exe is present in C:\windows\system32 If control.exe isn't there, go here, and download control.exe per the instructions at the site. IMPORTANT!: Please check your ActiveX security settings. They may have been changed by this CWS variant to allow ALL ActiveX!! If they have been changed, reset your active x security settings in IE as recommended here.
__________________ If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site. |
|
09-Aug-2004, 09:02 AM
#14 |
| OK thanks flrman1 - this is what I done and what happened: I Run Hijack This and I put a check by these and clicked fix checked: O2 - BHO: (no name) - {2E9CAFF6-30C7-4208-8807-E79D4EC6F806} - C:\Program Files\Submit\submithook.dll O4 - Startup: Gangsters2Setup.lnk = ? O4 - Startup: PowerReg SchedulerV2.exe I then restarted the computer. I then went to the link you provided to trendmicro and attempted to perfom an online scan but as the scan was being carried out, all my open internet windows dissappeared as if they had been closed and my ISP dial up window appeared from the taskbar asking if I wanted to disconnect from the internet. I tried an online scan a few times but the same thing kept happening at varying times through the scan. I don't think I have spybot installed so I don't think that part concerns me. I checked C:\windows\system32 for the file named Shell.dll and it was there. As a matter of interest I looked for system32/dllcache and I couldn't see this one and I checked a few times. I checked for control.exe in C:\windows\system32 and it was there. I then went and changed security settings as recommended at the link you gave. I think I still have a problem - here is my hijack this log after doing the above: Logfile of HijackThis v1.98.2 Scan saved at 13:01:32, on 09/08/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Norton Internet Security\NISUM.EXE C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\soundman.exe C:\Program Files\Panda Software\Panda Antivirus Titanium\AVENGINE.EXE C:\Program Files\ahead\InCD\InCD.exe C:\WINDOWS\System32\sistray.EXE C:\WINDOWS\System32\khooker.exe C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\Creative\Shared Files\CAMTRAY.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\System32\ctfmon.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\Norton Internet Security\ccPxySvc.exe C:\Program Files\Panda Software\Panda Antivirus Titanium\pavProxy.exe C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe C:\Program Files\Tesconet\Tesconet.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\FlashGet\flashget.exe C:\downloads\hijackthis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.tesco.net O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Messenger\ycomp.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: CCHelper Class - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Surf Pal\CCHelper.dll O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing) O2 - BHO: NavHelper Class - {C1E58A84-95B3-4630-B8C2-D06B77B7A0FC} - C:\Program Files\NavExcel\NavHelper\v2.0.4c\NHelper.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Panicware Surf &Pal - {0ADCDFE7-8490-406D-91BF-88F71FD7F8AE} - C:\Program Files\Panicware\Surf Pal\pwicc.dll O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Messenger\ycomp.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing) O4 - HKLM\..\Run: [SoundMan] soundman.exe O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe" O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE" /s O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE O4 - HKLM\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: Download &All by FD - fdiectx2.htm O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm O8 - Extra context menu item: Download with &FD - fdiectx.htm O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://www.tesco.net O15 - Trusted Zone: http://register-tesco.qa.business.ntl.com O15 - Trusted Zone: http://memberservices.tesco.net O16 - DPF: ChatSpace Full Java Client 3.1.0.229 - http://chat-a3.freeserve.com/Java/cfs31229.cab O16 - DPF: ChatSpace Full Java Client 4.0.0.300 - http://about.chatspace.com/Java/cfs40300.cab O16 - DPF: NTLSignup - https://tesco.autoregister.net/tesco/NTLSignup.cab O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab O16 - DPF: Yahoo! Chat 1.3 - http://cs8.chat.sc5.yahoo.com/c174/chat.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{D2B53267-BD24-48F0-9BCC-8FB5F987D7D8}: NameServer = 194.168.4.100 194.168.8.100 thanks |
09-Aug-2004, 09:19 AM
#15 | |||||
| I just read your other thread and it sounds like you have other issues here that are unrelated to the malware that was on the machine. I'm not the best at diagnosing hardware problems. Is it still restarting and freezing randomly? I'm heading off to work, but will be back on around 6pm EDT.
__________________ If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site. |

|
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |

| Thread Tools | |
| |
| You Are Using: |
Advertisements do not imply our endorsement of that product or service. All times are GMT -4. The time now is 05:32 PM. Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved. | |

