1
   

Help Thedevineass

 
 
Reply Wed 21 Apr, 2004 05:02 am
I had some problems with a computer witch was infected with the thebest virus, I think that I clean now, please check my log.

Logfile of HijackThis v1.97.7
Scan saved at 12:57:31, on 21-04-04
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\Symantec\Ghost\ngserver.exe
D:\NORMAN\nvc\bin\zanda.exe
D:\Symantec\Ghost\bin\dbserv.exe
D:\Symantec\Ghost\bin\rteng7.exe
D:\NORMAN\Nvc\BIN\NJEEVES.EXE
D:\NORMAN\Nvc\BIN\nvcoas.exe
D:\NORMAN\Nvc\BIN\NVCSCHED.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
D:\WinFax\WFXSWTCH.exe
C:\WINDOWS\System32\wfxsnt40.exe
D:\NORMAN\Nvc\BIN\ZLH.EXE
C:\WINDOWS\System32\ctfmon.exe
D:\NORMAN\Nvc\BIN\NYMSE.EXE
D:\WinFax\WFXCTL32.EXE
D:\NORMAN\Nvc\BIN\cclaw.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Kees\Local Settings\Temp\Temporary Directory 3 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\FlashGet\jccatch.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [WFXSwtch] D:\WinFax\WFXSWTCH.exe
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [NGServer] D:\Symantec\Ghost\ngserver.exe
O4 - HKLM\..\Run: [Norman ZANDA] D:\NORMAN\Nvc\BIN\ZLH.EXE /LOAD /SPLASH
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Controller.LNK = D:\WinFax\WFXCTL32.EXE
O4 - Global Startup: Microsoft Office.lnk = D:\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Download All by FlashGet - D:\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - D:\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: Research (HKLM)
O9 - Extra button: FlashGet (HKLM)
O9 - Extra 'Tools' menuitem: &FlashGet (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ncaonline.lokaal
O17 - HKLM\Software\..\Telephony: DomainName = ncaonline.lokaal
O17 - HKLM\System\CCS\Services\Tcpip\..\{19A807A3-613D-434E-9EBE-530C3050831D}: NameServer = 192.168.0.100,192.168.0.101
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ncaonline.lokaal
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = ncaonline.lokaal

Thanks for helping me.
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 1,210 • Replies: 11
No top replies

 
fishin
 
  1  
Reply Wed 21 Apr, 2004 09:48 am
It would appear that the offending entries have been properly removed.
0 Replies
 
timberlandko
 
  1  
Reply Wed 21 Apr, 2004 11:01 am
Yup ... looks clean. Now make sure your Windows, your IE, and your antivirus all are properly updated.
0 Replies
 
thedevineass
 
  1  
Reply Wed 21 Apr, 2004 11:32 am
They are, I keep a close I on that, speaking of it, my other (yes I have more then one) computer won't allow me to update the internet explorer to IE 6. Any suggestions?
0 Replies
 
timberlandko
 
  1  
Reply Wed 21 Apr, 2004 11:54 am
What security/privacy software, operating system and browser is on that machine, and what updates have been applied successfully so far?
0 Replies
 
thedevineass
 
  1  
Reply Wed 21 Apr, 2004 12:01 pm
Windows Me, and only AntiVir as securetty (shame, must improve that soon) and the Updates I run are the one's wich come automatically with windows, I also tryed to install it by downloading IE 6 and install it separate from the rest, but that didn't work either.
0 Replies
 
timberlandko
 
  1  
Reply Wed 21 Apr, 2004 12:30 pm
I'd try to uninstall/repair IE6 ... sounds like a file on your machine is corrupted or otherwise interfering with the install. One note ... the install is a hellaciously long affair, particularly on dialup. It might be that you figured the machine was hungup, or that the install failed, when it in fact was in progress.

This Knowledgebase article may help:
Uninstall Internet Explorer 6.0

If you do manage to get IE6 installed properly, there are some good setup tips in this Knowledgebase article:
Availability and Description of IE 6
0 Replies
 
thedevineass
 
  1  
Reply Wed 21 Apr, 2004 04:41 pm
Will you please look through this log, its from my other computer.


Logfile of HijackThis v1.97.7
Scan saved at 12:36:36, on 4/22/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 (5.50.4134.0100)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\SXGTKBAR.EXE
C:\PROGRAM FILES\AVPERSONAL\AVGCTRL.EXE
C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
K:\KAZAA LITE K++\KAZAA LITE K++\KAZAALITE.KPP
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
G:\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.50.0.250:80
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - I:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1043,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [SiSAudio] C:\WINDOWS\SYSTEM\MP_S3.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [DAEMON Tools-1033] "D:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SxgTkBar] SxgTkBar.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AVGCtrl] C:\PROGRA~1\AVPERS~1\AVGCTRL.EXE /min
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunServices: [ATIPOLAB] ati2evxx.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [ATIPOLL] ati2evxx.exe
O4 - HKLM\..\RunServices: [ATISmart] C:\WINDOWS\SYSTEM\ati2s9ag.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - HKLM\..\RunOnce: [WU2_RegSvr] C:\WINDOWS\SYSTEM\regsvr32.exe /s C:\WINDOWS\SYSTEM\WUAUPD98.DLL
O4 - HKLM\..\RunOnce: [UpdateHook] C:\WINDOWS\rundll32.exe AUHKNEW.DLL,RenameDll
O4 - HKLM\..\RunOnce: [WU4_RegSvr] C:\WINDOWS\SYSTEM\regsvr32.exe /s C:\WINDOWS\SYSTEM\AUHOOK.DLL
O4 - HKLM\..\RunOnce: [ReplaceCdmDll] command /C copy C:\WINDOWS\SYSTEM\cdmnew.dll C:\WINDOWS\SYSTEM\cdm.dll
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Startup: Doorgaan met Windows Update-installatie.lnk = C:\WINDOWS\Windows Update Setup-bestanden\ie6setup.exe
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37929.0203819444
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.euro.dell.com/global/apps/systemprofiler/PROFILER.CAB
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/14c52aa2a90beaab1e00/netzip/RdxIE601.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab27571.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab27571.cab

Thanks.
0 Replies
 
Craven de Kere
 
  1  
Reply Wed 21 Apr, 2004 07:59 pm
I'm trying to work through all outstanding logs and requests posted and only skimmed that log. Nothing jumped out at me but can you tell us if there's a problem on that puter?

If not, then it's probably fine. If you think it's infected I'll try to have another look.

As an aside, it's damn tedious to go through these logs, and one thing that really helps us is to keep each computer's logs in its own thread.

For you it's just your puter with a problem but for us one of many, and keeping it in separate threads helps us keep up with the many logs posted.
0 Replies
 
timberlandko
 
  1  
Reply Wed 21 Apr, 2004 11:02 pm
thedevineass, other than unupdated WinME and IE, I don't notice anything there that leaps out as a problem. Is this the machine that you're having trouble updating?


Craven de Kere wrote:
As an aside, it's damn tedious to go through these logs


Noticed that, didjya? Mr. Green
0 Replies
 
thedevineass
 
  1  
Reply Thu 22 Apr, 2004 12:22 pm
Sinds the problems whit that other computer (the first one I asked about) is solved, I think I'll keep it just by this topic if you don't mind sinds I already started here.

The problem with this computer is that I can't update or install IE 6, when I start it begins whit installing but it won't get any farder then 1% install for a while, then he jumps to 100% and gives the error that some files haven't been installed. I have closed everything, even in save mode tryed but it just stays the same, it's the only update I mis from windows update.

Thanks for helping me
0 Replies
 
timberlandko
 
  1  
Reply Thu 22 Apr, 2004 02:05 pm
Hmmmm ... a few ideas:

Could be a missing or corrupt file in IE5.5; have you tried the "Repair IE 5.5" option in Add/Remove Programs?

Could be related to your antivirus; have you tried disabling it prior to attempting the download?

Could be due to some other program running in the background (possibly even one that does not appear in Task Manager); as a workaround, you could try the IE6 installation from a "Clean Boot". You can effect a clean boot by going to Start > Run > type "msconfig" (without the quotes) > OK > General Tab, where you would click to clear the checkmarks from all options EXCEPT "Load Static VXDs" > Apply > OK, and then "Yes" to the "You must restart to apply your changes" (or whatever it says) prompt that will pop up. When the machine has booted up again, navigate to the IE download page and try the download again. If that works, reboot when prompted, wait untill the entire boot is accomplished, then go directly back to the General tab on the Configuration Utility and replace the checkmarks removed earlier, and reboot again.
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » Help Thedevineass
Copyright © 2025 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.06 seconds on 07/27/2025 at 03:09:47