1
   

Hijackthis log check

 
 
Reply Sun 25 Dec, 2005 01:32 pm
When my computer boots up, I get an error saying "Could not run WildTangent blah blah.dll" or something of the sort. A list of things I've done recently, should they be relevant to this:
- Installed new RAM
- Ran a disk cleanup on Windows XP, compressed old files

I've run Ad-aware and Spybot already.
Here's the log:

Logfile of HijackThis v1.99.1
Scan saved at 2:27:50 PM, on 12/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\WINDOWS\BCMSMMSG.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\RAMASST.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Jon\My Documents\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.centralva.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Centralva.net
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Mplay - {3ED8ACD1-583F-4ECE-B46F-FC4FA189E184} - C:\WINDOWS\System32\kbd20ka.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - C:\Program Files\RXToolBar\sfcont.dll (file missing)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\SYSTEM32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.centralva.net
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033001/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,15/mcgdmgr.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{05B30522-7935-4C92-91F0-B8C7F5E7F3F6}: NameServer = 64.203.136.14 64.203.136.13
O17 - HKLM\System\CS1\Services\Tcpip\..\{05B30522-7935-4C92-91F0-B8C7F5E7F3F6}: NameServer = 64.203.136.14 64.203.136.13
O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\Program Files\RXToolBar\sfcont.dll
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

Thanks.
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 815 • Replies: 3
No top replies

 
contrex
 
  1  
Reply Mon 26 Dec, 2005 09:42 am
What is Wild Tangent?

Wild Tangent is a video game software company specializing in online games. It has even made a partnership with AOL to include itself as part of the AOL Instant Messenger for their AIM games section. The WildTangent Web Driver is their technology that allows you to play 3D games over the Internet. Although its not technically considered spyware it does have built in components to update itself and gather information about the computer system including

* Operating System Version
* CPU Type and Speed
* Memory Amount
* Video Card type and Driver Version
* Sound Card type and Driver Version
* DirectX Version
* Location that the Web Driver was installed from

How do I Remove WildTangent?

Since WildTangent loads into the Windows Control Panel its a little more difficult to remove then some items. Follow the directions below to remove it or click on the link further down the page to download an automatic removal tool from the makers of WildTangent.

Manual Removal of Wild Tangent

1) Click on Start, Settings, Control Panel
2) Double-click on Add/Remove Programs
3) Click on the WildTangent selection and Change/Remove, Uninstall, or Add/Remove depending on the operating system. Then follow the onscreen prompts to remove the WT Driver.


4) Now run Hijackthis and fix or Remove the following line (if it exists)

04 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain

You may also have to use Hijackthis and remove the above line if you receive the following error message after using a spyware removal product to try to remove WildTangent

Error Loading C:\Program Files\WildTangent\apps\CDA\cdaEngine0400dll
This specified module could not be found


Follow the rest of these steps if the Control Panel icon or WildTangent folders still remain.

5) Remove the Wild Tangent Driver from the Control Panel if it still exists

* Click on Start, Run and type REGEDIT and press Enter
* Click on the Plus signs (+) next to the following sections
o HKEY_LOCAL_MACHINE
o SOFTWARE
o Microsoft
o Windows
o CurrentVersion
o Control Panel
o Cpls
* In the right hand column find the line for wtControlPanel, right click on it and Delete it
* Close the Windows Registry

6) Delete the WildTangent folder in Program Files and Windows

* Open My Computer
* Double-click on Drive C
* Double-click on Program Files
* Right-click on WildTangent and choose Delete (if the folder exists)
* Go back to Drive C and double-click on Windows
* Right-click on the WT folder and choose Delete (if the folder exists)

Automatic Removal of Wild Tangent

Click on the following link, download the program and run it to remove WildTangent from your system. This program can be found on the following removal page from WildTangent.

http://support.wildgames.com/uninstall.html

Alternate link to WildTangent Remover

WildTangent Remover
0 Replies
 
timberlandko
 
  1  
Reply Mon 26 Dec, 2005 01:15 pm
WildTangent itself is not strictly yuckware, but it and its associated games, etc, are vectors for yuckware infection. Getting rid of it and its assorted associated components is necessary, but is only a first step. A couple other things in that log that indicate work to be done are the existence of ViewpointManager and PartyPoker; again, in-and-of-themselves not malicious, but they are vectors for infection and should be dealt with. Specific instructions for safely removing these items is yours upon request. There are a couple other signatures in that log which indicate specific additional work to be done as well.

See This Topic.

If you wish to follow through with the proceedure laid out there, we can prolly help you with the several problems you have ... your call. The suggested method, while painstaking and tedious, was developed and tested over time and across multiple platforms; it is proven safe and effective and has resolved hundreds of similar issues. Continuing with this is up to you. Complete the preliminary steps - precisely and in the order and manner listed - and use the ""post reply" button to append the resultant logs and reports to this thread in the event you decide to follow through in that manner. You may find it convenient to click "Turn on email updates" down at the bottom right of this page; doing so will cause a notification to be sent to the email address you used when you registered with A2K whenever this topic receives a reply.
0 Replies
 
Don77
 
  1  
Reply Mon 26 Dec, 2005 05:40 pm
Word of caution here should you decide to go tinkering in the registry

Quote:
* Click on Start, Run and type REGEDIT and press Enter
* Click on the Plus signs (+) next to the following sections
o HKEY_LOCAL_MACHINE
o SOFTWARE
o Microsoft
o Windows
o CurrentVersion
o Control Panel
o Cpls
* In the right hand column find the line for wtControlPanel, right click on it and Delete it
* Close the Windows Registry


ALWAYS ALWAYS back up your registry prior to making any changes

How to backup and restore the entire registry:
http://service1.symantec.com/SUPPORT/ts...#_Section2


Personally I don't see a need to go digging in the registry unless your confident in what your doing, One wrong delete in there and you could have a non functioning computer

I would remove it from Add/Remove program and then run Ad-aware to let it clean up the registry for you

But hey thats just me Very Happy
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » Hijackthis log check
Copyright © 2024 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.04 seconds on 05/06/2024 at 04:20:19