1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Can you check my hijackthis log?

Discussion in 'Virus & Other Malware Removal' started by schecterc1, Sep 11, 2003.

Thread Status:
Not open for further replies.
Advertisement
  1. schecterc1

    schecterc1 Thread Starter

    Joined:
    Sep 11, 2003
    Messages:
    3
    Im fighting with global finder and incredifind. Don't know where they came from. Possibly something my 10-year-old downloaded. Could you check my hijackthis log and give me some suggestions?

    thanks,

    jeff

    Logfile of HijackThis v1.97.1
    Scan saved at 9:47:15 PM, on 9/11/03
    Platform: Windows 98 Gold (Win9x 4.10.1998)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\MDM.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
    C:\PROGRAM FILES\WINAMP3\WINAMPA.EXE
    C:\WINDOWS\LOADQM.EXE
    C:\PROGRAM FILES\ADAPTEC\EASY CD CREATOR 4\CREATECD\CREATECD.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\WINDOWS\SYSTEM\PSTORES.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

    R3 - URLSearchHook: eUnivBHO Class - {269B6797-664E-48AA-B283-B012BDF6E525} - C:\PROGRA~1\INCRED~1\BHO\BHO.DLL
    O1 - Hosts: 66.159.20.80 www1.ndhosting.com
    O1 - Hosts: 66.159.20.80 www3.ndhosting.com
    O1 - Hosts: 66.159.20.80 www2.ndhosting.com
    O1 - Hosts: 66.159.20.80 www.ndhosting.com
    O1 - Hosts: 66.159.20.80 www.kinghost.com
    O1 - Hosts: 66.159.20.80 kinghost.com
    O1 - Hosts: 66.159.20.80 www1.kinghost.com
    O1 - Hosts: 66.159.20.80 www2.kinghost.com
    O1 - Hosts: 66.159.20.80 www3.kinghost.com
    O1 - Hosts: 66.159.20.80 www4.kinghost.com
    O1 - Hosts: 66.159.20.80 www5.kinghost.com
    O1 - Hosts: 66.159.20.80 www6.kinghost.com
    O1 - Hosts: 66.159.20.80 www7.kinghost.com
    O1 - Hosts: 66.159.20.80 www8.kinghost.com
    O1 - Hosts: 66.159.20.80 www9.kinghost.com
    O1 - Hosts: 66.159.20.80 www10.kinghost.com
    O1 - Hosts: 66.159.20.80 www.smutserver.com
    O1 - Hosts: 66.159.20.80 smutserver.com
    O1 - Hosts: 66.159.20.80 www1.smutserver.com
    O1 - Hosts: 66.159.20.80 www2.smutserver.com
    O1 - Hosts: 66.159.20.80 www16.smutserver.com
    O1 - Hosts: 66.159.20.80 www3.smutserver.com
    O1 - Hosts: 66.159.20.80 www4.smutserver.com
    O1 - Hosts: 66.159.20.80 www5.smutserver.com
    O1 - Hosts: 66.159.20.80 www6.smutserver.com
    O1 - Hosts: 66.159.20.80 www7.smutserver.com
    O1 - Hosts: 66.159.20.80 www8.smutserver.com
    O1 - Hosts: 66.159.20.80 www9.smutserver.com
    O1 - Hosts: 66.159.20.80 www10.smutserver.com
    O1 - Hosts: 66.159.20.80 www11.smutserver.com
    O1 - Hosts: 66.159.20.80 www12.smutserver.com
    O1 - Hosts: 66.159.20.80 www13.smutserver.com
    O1 - Hosts: 66.159.20.80 www14.smutserver.com
    O1 - Hosts: 66.159.20.80 www15.smutserver.com
    O1 - Hosts: 66.159.20.80 www17.smutserver.com
    O1 - Hosts: 66.159.20.80 www18.smutserver.com
    O1 - Hosts: 66.159.20.80 www19.smutserver.com
    O1 - Hosts: 66.159.20.80 www20.smutserver.com
    O1 - Hosts: 66.159.20.80 www21.smutserver.com
    O1 - Hosts: 66.159.20.80 www22.smutserver.com
    O1 - Hosts: 66.159.20.80 www23.smutserver.com
    O1 - Hosts: 66.159.20.80 www24.smutserver.com
    O1 - Hosts: 66.159.20.80 www25.smutserver.com
    O1 - Hosts: 66.159.20.80 www26.smutserver.com
    O1 - Hosts: 66.159.20.80 www27.smutserver.com
    O1 - Hosts: 66.159.20.80 www28.smutserver.com
    O1 - Hosts: 66.159.20.80 www29.smutserver.com
    O1 - Hosts: 66.159.20.80 www30.smutserver.com
    O1 - Hosts: 66.159.20.80 www31.smutserver.com
    O1 - Hosts: 66.159.20.80 www32.smutserver.com
    O1 - Hosts: 66.159.20.80 agreathost.net
    O1 - Hosts: 66.159.20.80 www.agreathost.net
    O1 - Hosts: 66.159.20.80 hotfreehost.com
    O1 - Hosts: 66.159.20.80 www.hotfreehost.com
    O1 - Hosts: 66.159.20.80 greatfreehost.com
    O1 - Hosts: 66.159.20.80 www.greatfreehost.com
    O1 - Hosts: 66.159.20.80 freesmutpages.com
    O1 - Hosts: 66.159.20.80 www.freesmutpages.com
    O1 - Hosts: 66.159.20.80 apornhost.com
    O1 - Hosts: 66.159.20.80 www.apornhost.com
    O1 - Hosts: 66.159.20.80 nasty-pages.com
    O1 - Hosts: 66.159.20.80 www.nasty-pages.com
    O1 - Hosts: 66.159.20.80 sexyfreehost.com
    O1 - Hosts: 66.159.20.80 www.sexyfreehost.com
    O1 - Hosts: 66.159.20.80 x4web.com
    O1 - Hosts: 66.159.20.80 www.x4web.com
    O1 - Hosts: 66.159.20.80 sexplanets.com
    O1 - Hosts: 66.159.20.80 www.sexplanets.com
    O1 - Hosts: 66.159.20.80 maxismut.com
    O1 - Hosts: 66.159.20.80 www.maxismut.com
    O1 - Hosts: 66.159.20.80 tgpfriendly.com
    O1 - Hosts: 66.159.20.80 www.tgpfriendly.com
    O1 - Hosts: 66.159.20.80 tgp-server.com
    O1 - Hosts: 66.159.20.80 www.tgp-server.com
    O1 - Hosts: 66.159.20.80 magnaplza.com
    O1 - Hosts: 66.159.20.80 www.magnaplza.com
    O1 - Hosts: 66.159.20.80 free-xxx-server.com
    O1 - Hosts: 66.159.20.80 www.free-xxx-server.com
    O1 - Hosts: 66.159.20.80 libereco.net
    O1 - Hosts: 66.159.20.80 www.libereco.net
    O1 - Hosts: 66.159.20.80 0190-dialer.com
    O1 - Hosts: 66.159.20.80 www.0190-dialer.com
    O1 - Hosts: 66.159.20.80 xxxod.net
    O1 - Hosts: 66.159.20.80 www.xxxod.net
    O1 - Hosts: 66.159.20.80 altsights.com
    O1 - Hosts: 66.159.20.80 www.altsights.com
    O1 - Hosts: 66.159.20.80 adulthosting.com
    O1 - Hosts: 66.159.20.80 www.adulthosting.com
    O1 - Hosts: 66.159.20.80 superhova.com
    O1 - Hosts: 66.159.20.80 www.superhova.com
    O1 - Hosts: 66.159.20.80 bestpornhost.com
    O1 - Hosts: 66.159.20.80 www.bestpornhost.com
    O1 - Hosts: 66.159.20.80 hostingfree.com
    O1 - Hosts: 66.159.20.80 www.hostingfree.com
    O1 - Hosts: 66.159.20.80 xfreehosting.com
    O1 - Hosts: 66.159.20.80 www.xfreehosting.com
    O1 - Hosts: 66.159.20.80 blinghosting.com
    O1 - Hosts: 66.159.20.80 www.blinghosting.com
    O1 - Hosts: 66.159.20.80 x-x-x-hosting.com
    O1 - Hosts: 66.159.20.80 www.x-x-x-hosting.com
    O1 - Hosts: 66.159.20.80 pornparks.com
    O2 - BHO: NavErrRedir Class - {269B6797-664E-48AA-B283-B012BDF6E525} - C:\PROGRA~1\INCRED~1\BHO\BHO.DLL
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
    O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
    O4 - HKLM\..\Run: [CreateCD] C:\PROGRA~1\ADAPTEC\EASYCD~1\CREATECD\CREATECD.EXE -r
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
    O4 - HKLM\..\RunServices: [HC Reminder] hc.exe
    O4 - HKLM\..\RunServices: [BCDetect] C:\WINDOWS\SYSTEM\BCDetect.exe defer
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: Open Picture in &Microsoft PhotoDraw - res://C:\PROGRA~1\MICROS~1\OFFICE\1033\PHDINTL.DLL/phdContext.htm
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
    O12 - Plugin for .au: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
    O12 - Plugin for .wav: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {DED22F57-FEE2-11D0-953B-00C04FD9152D} (CarPoint Auto-Pricer Control) - http://autos.msn.com/components/ocx/autopricer/autopricer.cab
    O16 - DPF: Yahoo! Graffiti - http://download.games.yahoo.com/games/clients/y/grt5_x.cab
    O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
    O16 - DPF: {36C66BBD-E667-4DAD-9682-58050E7C9FDC} (CDKey Class) - http://www.cdkeybonus.com/cdkey/ITCDKey.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37863.8392361111
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
    O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.140/code/PWActiveXImgCtl.CAB
    O16 - DPF: {76D90D08-EAB7-46D8-BF99-87445BF59E72} (SystemInfo Class) - http://www.getdway.com/dwayready/dpcsysinfo.cab
    O16 - DPF: {142016BF-5CCA-4C8D-AC01-C4A8F4044AD5} - http://media.euniverse.com/cursorzone/files/Cat_Running_setup_td035.cab
     
  2. Top Banana

    Top Banana

    Joined:
    Nov 10, 2002
    Messages:
    1,344
    Scan with HijackThis, put a checkmark at and "Fix checked" the following entries. Close all windows except HijackThis before fixing.

    R3 - URLSearchHook: eUnivBHO Class - {269B6797-664E-48AA-B283-B012BDF6E525} - C:\PROGRA~1\INCRED~1\BHO\BHO.DLL
    O1 - Hosts: 66.159.20.80 www1.ndhosting.com
    O1 - Hosts: 66.159.20.80 www3.ndhosting.com
    O1 - Hosts: 66.159.20.80 www2.ndhosting.com
    O1 - Hosts: 66.159.20.80 www.ndhosting.com
    O1 - Hosts: 66.159.20.80 www.kinghost.com
    O1 - Hosts: 66.159.20.80 kinghost.com
    O1 - Hosts: 66.159.20.80 www1.kinghost.com
    O1 - Hosts: 66.159.20.80 www2.kinghost.com
    O1 - Hosts: 66.159.20.80 www3.kinghost.com
    O1 - Hosts: 66.159.20.80 www4.kinghost.com
    O1 - Hosts: 66.159.20.80 www5.kinghost.com
    O1 - Hosts: 66.159.20.80 www6.kinghost.com
    O1 - Hosts: 66.159.20.80 www7.kinghost.com
    O1 - Hosts: 66.159.20.80 www8.kinghost.com
    O1 - Hosts: 66.159.20.80 www9.kinghost.com
    O1 - Hosts: 66.159.20.80 www10.kinghost.com
    O1 - Hosts: 66.159.20.80 www.smutserver.com
    O1 - Hosts: 66.159.20.80 smutserver.com
    O1 - Hosts: 66.159.20.80 www1.smutserver.com
    O1 - Hosts: 66.159.20.80 www2.smutserver.com
    O1 - Hosts: 66.159.20.80 www16.smutserver.com
    O1 - Hosts: 66.159.20.80 www3.smutserver.com
    O1 - Hosts: 66.159.20.80 www4.smutserver.com
    O1 - Hosts: 66.159.20.80 www5.smutserver.com
    O1 - Hosts: 66.159.20.80 www6.smutserver.com
    O1 - Hosts: 66.159.20.80 www7.smutserver.com
    O1 - Hosts: 66.159.20.80 www8.smutserver.com
    O1 - Hosts: 66.159.20.80 www9.smutserver.com
    O1 - Hosts: 66.159.20.80 www10.smutserver.com
    O1 - Hosts: 66.159.20.80 www11.smutserver.com
    O1 - Hosts: 66.159.20.80 www12.smutserver.com
    O1 - Hosts: 66.159.20.80 www13.smutserver.com
    O1 - Hosts: 66.159.20.80 www14.smutserver.com
    O1 - Hosts: 66.159.20.80 www15.smutserver.com
    O1 - Hosts: 66.159.20.80 www17.smutserver.com
    O1 - Hosts: 66.159.20.80 www18.smutserver.com
    O1 - Hosts: 66.159.20.80 www19.smutserver.com
    O1 - Hosts: 66.159.20.80 www20.smutserver.com
    O1 - Hosts: 66.159.20.80 www21.smutserver.com
    O1 - Hosts: 66.159.20.80 www22.smutserver.com
    O1 - Hosts: 66.159.20.80 www23.smutserver.com
    O1 - Hosts: 66.159.20.80 www24.smutserver.com
    O1 - Hosts: 66.159.20.80 www25.smutserver.com
    O1 - Hosts: 66.159.20.80 www26.smutserver.com
    O1 - Hosts: 66.159.20.80 www27.smutserver.com
    O1 - Hosts: 66.159.20.80 www28.smutserver.com
    O1 - Hosts: 66.159.20.80 www29.smutserver.com
    O1 - Hosts: 66.159.20.80 www30.smutserver.com
    O1 - Hosts: 66.159.20.80 www31.smutserver.com
    O1 - Hosts: 66.159.20.80 www32.smutserver.com
    O1 - Hosts: 66.159.20.80 agreathost.net
    O1 - Hosts: 66.159.20.80 www.agreathost.net
    O1 - Hosts: 66.159.20.80 hotfreehost.com
    O1 - Hosts: 66.159.20.80 www.hotfreehost.com
    O1 - Hosts: 66.159.20.80 greatfreehost.com
    O1 - Hosts: 66.159.20.80 www.greatfreehost.com
    O1 - Hosts: 66.159.20.80 freesmutpages.com
    O1 - Hosts: 66.159.20.80 www.freesmutpages.com
    O1 - Hosts: 66.159.20.80 apornhost.com
    O1 - Hosts: 66.159.20.80 www.apornhost.com
    O1 - Hosts: 66.159.20.80 nasty-pages.com
    O1 - Hosts: 66.159.20.80 www.nasty-pages.com
    O1 - Hosts: 66.159.20.80 sexyfreehost.com
    O1 - Hosts: 66.159.20.80 www.sexyfreehost.com
    O1 - Hosts: 66.159.20.80 x4web.com
    O1 - Hosts: 66.159.20.80 www.x4web.com
    O1 - Hosts: 66.159.20.80 sexplanets.com
    O1 - Hosts: 66.159.20.80 www.sexplanets.com
    O1 - Hosts: 66.159.20.80 maxismut.com
    O1 - Hosts: 66.159.20.80 www.maxismut.com
    O1 - Hosts: 66.159.20.80 tgpfriendly.com
    O1 - Hosts: 66.159.20.80 www.tgpfriendly.com
    O1 - Hosts: 66.159.20.80 tgp-server.com
    O1 - Hosts: 66.159.20.80 www.tgp-server.com
    O1 - Hosts: 66.159.20.80 magnaplza.com
    O1 - Hosts: 66.159.20.80 www.magnaplza.com
    O1 - Hosts: 66.159.20.80 free-xxx-server.com
    O1 - Hosts: 66.159.20.80 www.free-xxx-server.com
    O1 - Hosts: 66.159.20.80 libereco.net
    O1 - Hosts: 66.159.20.80 www.libereco.net
    O1 - Hosts: 66.159.20.80 0190-dialer.com
    O1 - Hosts: 66.159.20.80 www.0190-dialer.com
    O1 - Hosts: 66.159.20.80 xxxod.net
    O1 - Hosts: 66.159.20.80 www.xxxod.net
    O1 - Hosts: 66.159.20.80 altsights.com
    O1 - Hosts: 66.159.20.80 www.altsights.com
    O1 - Hosts: 66.159.20.80 adulthosting.com
    O1 - Hosts: 66.159.20.80 www.adulthosting.com
    O1 - Hosts: 66.159.20.80 superhova.com
    O1 - Hosts: 66.159.20.80 www.superhova.com
    O1 - Hosts: 66.159.20.80 bestpornhost.com
    O1 - Hosts: 66.159.20.80 www.bestpornhost.com
    O1 - Hosts: 66.159.20.80 hostingfree.com
    O1 - Hosts: 66.159.20.80 www.hostingfree.com
    O1 - Hosts: 66.159.20.80 xfreehosting.com
    O1 - Hosts: 66.159.20.80 www.xfreehosting.com
    O1 - Hosts: 66.159.20.80 blinghosting.com
    O1 - Hosts: 66.159.20.80 www.blinghosting.com
    O1 - Hosts: 66.159.20.80 x-x-x-hosting.com
    O1 - Hosts: 66.159.20.80 www.x-x-x-hosting.com
    O1 - Hosts: 66.159.20.80 pornparks.com
    O2 - BHO: NavErrRedir Class - {269B6797-664E-48AA-B283-B012BDF6E525} - C:\PROGRA~1\INCRED~1\BHO\BHO.DLL
    O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
    O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.140/code/PWActiveXImgCtl.CAB
    O16 - DPF: {142016BF-5CCA-4C8D-AC01-C4A8F4044AD5} - http://media.euniverse.com/cursorzo...setup_td035.cab

    Delete C:\Program Files\Incredifind folder.
     
  3. schecterc1

    schecterc1 Thread Starter

    Joined:
    Sep 11, 2003
    Messages:
    3
    Thank you so much! I did as you said and so far all's well. I hope I never see Incredifind and Global finder again.
     
  4. $teve

    $teve

    Joined:
    Oct 9, 2001
    Messages:
    9,396
    and dont be too hard on your daughter.........................these things have a habit of finding their way on to your pc without asking and without you even knowing.

    take care

    ;)
     
  5. schecterc1

    schecterc1 Thread Starter

    Joined:
    Sep 11, 2003
    Messages:
    3
    Thanks. I'll let her slide this time. It's been over 24 hours and I am still proudly Incredifind and Global finder free!
     
  6. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/164160

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice