0
   

Dear god, its me shewolf. Hijak log

 
 
Reply Tue 22 Feb, 2005 05:07 pm
HAHAAA!!! told ya I'd do it. Laughing

My computer is slow, not connecting to the internet , web pages dont open . Often times I am getting error messages or it just freezes in the website.
I get the error message of " can not connect to server with current proxy settings"
I have run AdwareSe, Spybot, have given spyware guard an update with in the last 3 days.
Actually.. they have ALL been updated in the last 3 days. And I have used the website scans you have given me before...
>sigh<


here is my log:
Logfile of HijackThis v1.98.2
Scan saved at 5:04:36 PM, on 2/22/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\Program Files\McAfee\McAfee Firewall\CPDCLNT.EXE
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\McAfee\McAfee VirusScan\Webscanx.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\EarthLink TotalAccess\FastLane\IPClient.exe
C:\Program Files\EarthLink TotalAccess\Accelerator\ElinkAcc.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\DOCUME~1\Dawn\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie/button/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://start.earthlink.net/AL/Search
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.earthlink.net/partner/more/msie/button/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.able2know.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.earthlink.net/AL/Search
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080
R3 - URLSearchHook: SrchHook Class - {44F9B173-041C-4825-A9B9-D914BD9DCBB3} - C:\Program Files\EarthLink TotalAccess\ElnIE.dll
R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: PnIEBrowserHelperObj Class - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: EarthLink Toolbar - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\EarthLink TotalAccess\Accelerator\\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\EarthLink TotalAccess\Accelerator\\pac-image.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A2717D41-700E-4FC8-A6B9-F3B9367D7D55}: NameServer = 207.69.188.185 207.69.188.186
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 0 • Views: 1,952 • Replies: 22
No top replies

 
shewolfnm
 
  1  
Reply Thu 24 Feb, 2005 11:39 am
bump
0 Replies
 
cjhsa
 
  1  
Reply Thu 24 Feb, 2005 11:45 am
Wow, I'm not seeing anything in there that looks all that bad, though I'm not a fan of AIM. Where's Don anyway?

You can try opening a DOS window and running "msconfig", then select the "Startup" tab and turn off things you think you don't need. See if that helps.

Disabling or uninstalling AIM is always a good bet too.
0 Replies
 
shewolfnm
 
  1  
Reply Thu 24 Feb, 2005 11:50 am
i did the msconfig, and turned off a few things but i am still running REALLLY slow. so i dunno?
I use aim to keep in touch with momma so as much as i hate anything that has to do with aol, that prog stays. Laughing
0 Replies
 
cjhsa
 
  1  
Reply Thu 24 Feb, 2005 12:04 pm
Why not use MSM or YIM instead? Fewer problems. AIM sucks, basically a virus.
0 Replies
 
cjhsa
 
  1  
Reply Thu 24 Feb, 2005 12:05 pm
Have you installed anything recently or made any configuration changes to your system (i.e. anti-spy, anti-virus settings)?
0 Replies
 
shewolfnm
 
  1  
Reply Thu 24 Feb, 2005 12:11 pm
no. but this has been going on since i discovered a virus about 3 weeks ago.
All of my anti spyware says there isnt anything to be found, but my computer is still acting the same.
0 Replies
 
cjhsa
 
  1  
Reply Thu 24 Feb, 2005 12:28 pm
Boot it in safe mode and run full virus and anti-spy scans.
0 Replies
 
Slappy Doo Hoo
 
  1  
Reply Thu 24 Feb, 2005 12:31 pm
How is AIM like a virus? Just curious.
0 Replies
 
cjhsa
 
  1  
Reply Thu 24 Feb, 2005 12:36 pm
Ever seen a teenager use AIM? It's like an addictive virus.

Plus, it doesn't play well with Windows. Nothing AOL ever created plays well with Windows. I am often forced to reboot my XP Home machine because of one of my kids leaving AIM running then switching users. It causes all sorts of problems.
0 Replies
 
Slappy Doo Hoo
 
  1  
Reply Thu 24 Feb, 2005 01:00 pm
Just wondering...I have it on my computer, and wasn't sure if it's going to screw anything up.
0 Replies
 
squinney
 
  1  
Reply Thu 24 Feb, 2005 02:38 pm
Shewolf - Calling on God? Suuuuure! NOW you wanna believe! Give her a little computer problem and she runs calling for God! Laughing

Oh, wait... I think He's coming.

See ya!
0 Replies
 
shewolfnm
 
  1  
Reply Thu 24 Feb, 2005 02:40 pm
quick,
god is comming
look busy!
> walks away whistleing <
0 Replies
 
cjhsa
 
  1  
Reply Thu 24 Feb, 2005 03:03 pm
Any luck?
0 Replies
 
shewolfnm
 
  1  
Reply Thu 24 Feb, 2005 03:04 pm
nada.
0 Replies
 
cjhsa
 
  1  
Reply Thu 24 Feb, 2005 03:11 pm
Get McAfee Stinger. It's a free virus removal tool and it works really well.

http://vil.nai.com/vil/stinger/
0 Replies
 
shewolfnm
 
  1  
Reply Thu 24 Feb, 2005 03:20 pm
i will do that.
thank you...
donkey. ;-)
0 Replies
 
cjhsa
 
  1  
Reply Thu 24 Feb, 2005 04:00 pm
Let me know what you find.
0 Replies
 
timberlandko
 
  1  
Reply Thu 24 Feb, 2005 09:01 pm
shewolfnm, from the log you posted, I'm not real sure there's gonna be much if any spyware/adware to find, but if ya wanna, I'm willin' to take a shot at figurin'out and fixin' your problems. To begin with, I'd like to rule out some stuff. This is gonna get sorta detailed, so you'll prolly wanna print out these instructions.

Assumin' you've done what you can with Spybot S&D and Ad Aware SE, we'll skip them for the moment. BTW, Spyware Guard hasn't had an update in over a year - I hope you mean Spyware Blaster (http://www.javacoolsoftware.com/spywareblaster.html}. If not, get it, have it check for updates, and run it.

Anyhow, lets get to work here. First, I'd like you to go to Trend Housecall (http://housecall.trendmicro.com) . Disable any virus protection and firewall, and any active antispyware you have on your system, then click on "Scan Now. It's Free!" When the next window opens, select your country, and click "Go". If a security alert comes up asking you if you want to install an application, grant permission. It will take a while for the scanner to download and install. Read and follow the instructions to run a full scan of your system. The scanning will take a good while. When it is complete, allow it to clean or remove whatever, if anything, it found. It'll take a good while to run to completion; be patient. Read a book, walk the dog, or go watch TV or somethin'. When its done, if it says it has found "Uncleanable" files, note the full path and filename of them. Write them down. Reboot if it asks you to.

If it has found files it says it can't clean, reboot into safe mode (reboot - as soon as your machine has shut down, begin tapping the F8 key. Eventually, you'll be presented with a black&white Boot Menu. Using your arrow pad or number pad, select "Safe Mode" and hit "Enter". If given the option to log on as "Administrator", do so, otherwise log on to your usual Windows account. Your desktop will look wierd, but never mind. Configure Explorer to Show All Files and Folders (Open "My Computer", select "Tools" and click "Folder Options ", select the "View" tab. Under the "Hidden files and folders" heading, select "Show hidden files and folders". Uncheck the "Hide protected operating system files (recommended)" option. Click Yes to confirm, Click "OK" and exit. Click "Start", and open "Search", select "Search for all files and folders", and enter the first, if any, filename you wrote down from Housecall's "Could not clean" list. Set "Look in" to search all of your hard drives (that should be the option first presented, but check just to make sure). Click "More Advanced Options", and be sure "Search system folders", "Search hidden files and folders", and "Search subfolders" are checked. Now, conduct the search for the named file. When found, right click on the filename, and delete it. If it won't let you delete it, don't get upset, just note which file it is, and search for the next, if any, file from your list. Continue 'til done. When finished, reboot normally.

Now go to Panda Active Scan (http://www.pandasoftware.com/activescan/com/activescan_principal.htm), and again with your antivirus, firewall, and any antispyware apps disabled, follow the instructions to run a complete scan of your system (which again will take a good while), letting it clean or remove whatever, if anything, it finds, and, again as above, manually deleting while in safe mode whatever, if anything, it says it couldn't clean, noting anything you cauldn't delete.

Next, go to Windows Update (http://v5.windowsupdate.microsoft.com) and be certain your Windows is fully updated. When thats done, do the same at Office Update (http://office.microsoft.com/officeupdate).

When done with that, go to Microsoft Security (http://www.microsoft.com/security/default.mspx), and read, understand, and follow the instructions to run the Microsoft Malicious Software Removal Tool (http://www.microsoft.com/security/malwareremove/default.mspx). It shouldn't take very long to run. It will give you a report when it has finished. If it tells you anything other than that it found nothing, please note what it says it found, and what it says it did about it.

When done, download, install, and run a complete system scan with Microsoft Antispyware (http://www.microsoft.com/athome/security/spyware/software/default.mspx).

There also is a recent update for MSN Messenger, if you use it, it should bave prompted you to update, but just to be certain, go to the MSN Messenger Website (http://messenger.msn.com), and follow the instructions to verify you have the latest version.

With all of that out of the way, download, install, and run Cleanup, (http://cleanup.stevengould.org). When its done - it too is gonna take a while - reboot normally.

Now, go to Start > Settings > Control Panel > Add/Remove Programs, and find and uninstal the HiJackThis version you've got. Then go back to your desktop and delete the HiJackhis folder there. Next, create a folder named somethin' like "HJT" on your root drive (the drive on which Windows resides - with WinXP, its usually "Local Disk C:\"). To do so, hold down the left Windows key and while holdin' it, hit the letter "E" - find and open (double click) your root drive's folder. From that folder's toolbar, click "File", select "Folder", name the folder somethin' like "HJT", and exit. Now, Get the current version of HiJackThis.

Download it to the folder you've just made, extract it, and, WITH NO OTHER WINDOWS OR BROWSERS RUNNING run it. The first window that opens will offer you several options. Please click the last option shown, ""None of the above, just start the program". At the lower right of the next window that opens, in the panel named "Other Stuff", click "Config..." Under that window's first page, "Main", be certain ONLY the 2cnd and 3rd boxes, "Make Backups before fixing items" and "Confirm fixing & ignoring of items (safe mode}, and the 4th and 5th boxes, ""Include list of running processes in logfiles" and "Show intro frame at startup" are checked. Be certain. Now, up at the top right of that window, click the 4th button, "Misc Tools". Place a checkmark in the boxes labled "List also minor sections (full) and "list empty sections (complete), the click the "Generate Startup log". A confirmation box will pop up asking you if you wish to continue. Click "Yes". After a few moments, a Notepad window with a buncha stuff in it will open. It will be named "Startuplist.txt". Click "File" in the Notepad window's toolbar and select "Save". That will save the list to the HJT folder. Close Notepad. At the lower right of the HJT window, click "Back". In the next window, click "Scan". When the scan has completed, the "Scan" button will have changed to "Save log", click it to do so. When the log has been saved, exit the program, WITHOUT FIXING ANYTHING.

Now, find the HJT folder again, open it, find "startuplist.txt" and hijackthis.log", and post them here, along with with the results of all the other actions you have taken as listed above, including the full path and filename of all, if any, files you were unable to delete. When all of that has been done, we'll have a pretty good idea of what your problems aren't, and we can begin to go after what they might be.


Embarrassed edited to fix a link .... damn, I gotta learn to use Preview Embarrassed
0 Replies
 
shewolfnm
 
  1  
Reply Fri 25 Feb, 2005 08:43 am
Thanks timber.
I will start on this today and post my progress as I go.
Since I am on dial up, i probally wont be finished until this evening!! Laughing
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » Dear god, its me shewolf. Hijak log
Copyright © 2024 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.05 seconds on 04/26/2024 at 09:40:54