HiJack This?

Reply Mon 24 May, 2004 07:07 pm
Long story short I had a virus and fixed it with Norton but I still think that there are other things going on. I don't know what to look for in HiJack this. I have pasted it below. Could someone please read it and let me know what to fix. Any help would be most appreciated.

Logfile of HijackThis v1.97.7
Scan saved at 8:58:09 PM, on 5/28/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\wmconnect\wmtray.exe
C:\Program Files\Microsoft Office\Office10\msoffice.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\wmconnect\wwm.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\eric\Local Settings\Temp\Temporary Directory 5 for cwshredder.zip\CWShredder.exe
C:\Documents and Settings\eric\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Wal-Mart Connect Tray Icon.lnk = C:\Program Files\wmconnect\wmtray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: DigiChat Applet - http://host5.digichat.com/DigiChat/DigiClasses/Client_IE.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/1435/ftp.coupons.com/v3123/cpbrkpie.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38028.8036458333
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedContent/common/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{53114895-DB9B-4EE5-BD38-4CADA3A48F65}: NameServer =
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 1,583 • Replies: 11
No top replies

cicerone imposter
Reply Mon 24 May, 2004 09:23 pm
eng, Welcome to A2K. You need assistance from Craven or timberlanko. They are the experts.
0 Replies
Reply Tue 25 May, 2004 02:33 pm
Who are Craven or timberlanko? Will they look at this post or do I need to post elsewhere
0 Replies
Reply Tue 25 May, 2004 02:36 pm
It's in 'Internet' so they will probably find it. Just give it a little time.
0 Replies
Craven de Kere
Reply Tue 25 May, 2004 03:22 pm
Re: HiJack This?
Monger and Nirvana are experts in this as well (actually I only started helping because monger was travelling, he'd been handling these by himself almost). I'm way too tired to do an exhaustive fix but from a very quick look I'd say it's pretty clean. I have my suspicions on a few items but can't research them now.

Are you having any spyware problems?
0 Replies
Reply Wed 26 May, 2004 03:44 am
That's a clean log! :wink:
0 Replies
Reply Wed 26 May, 2004 03:27 pm
I have been using adaware, norton and others regularly. I am still having problems with internet explorer hanging up. Most recently when I try to delete my internet history using control panel/internet options/clear history the history files are still viewable in norton system works/web tools/advanced cleanup (2004 version). I mentioned the internet explorer hangup, I know that it hangs up because when I click on the begin quick clean button after running IE I get a message stating that I still have a window open (none visible even in ctl/alt/del applications window). I am not sure if I still have a bug in the system or permanent changes were made when I did have the virus (eliminated following directions from norton)(Backdoor.Rsbot). Thanks for the comments so far. I really appreciate your help.
0 Replies
Reply Thu 27 May, 2004 01:56 am
Disable system restore then run a full scan with Norton. Do the scan in safe mode. Re-enable system restore afterwards.
0 Replies
Reply Sat 29 May, 2004 07:02 pm
I attempted to use safe mode and do a full scan. When I got into safe mode I opened Norton and tried to open all of the functions to run each utility. Only the one button checkup was functioning. I could not get another function to work. I liked the idea of using safe mode but not able to get the results that I wanted. Thanks for the advice. I will be happy to try another suggestions. Thanks again for the responses.
0 Replies
Reply Tue 1 Jun, 2004 01:06 am
Run one of the following on-line virus scans: Housecall or Bitdefender

Norton may have to be re-installed if you are virus free.
0 Replies
Reply Sat 5 Jun, 2004 09:57 am
I ran the Housecall antivirus and I was virus free. I then proceeded uninstall norton system works and antivirus. I ran a search on my computer and found that a lot of folders and registry keys and registry folders were left by norton, symantec. I proceeded to delete everything that I could find. There were two keys and two registry folders that I could not delete, they were protected. I reloaded the programs and still do not have the ability to run Norton disk Doctor and I still have problems with web clean up/begin quick clean stating that I still have IE open. Is there a way to find out what is happening in the background besides the task manager/process tab?
0 Replies
Reply Sat 5 Jun, 2004 11:48 am
If you have a Norton disk you should be able to install over the top of the other app. Try that.
0 Replies

Related Topics

YouTube Is Doomed - Discussion by Shapeless
So I just joined Facebook.... - Discussion by DrewDad
Internet disinformation overload - Discussion by rosborne979
Participatory Democracy Online - Discussion by wandeljw
OpenDNS and net neutrality - Question by Butrflynet
Internet Explorer 8? - Question by Pitter
  1. Forums
  2. » HiJack This?
Copyright © 2024 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.04 seconds on 09/29/2024 at 02:23:28