1
   

Just to be certain regarding use of HijackThis

 
 
roaddog
 
Reply Thu 1 Mar, 2007 04:32 pm
First: Hi all:-)
Just registered to Able2know and it seems real proffesional...
So...the problem: i just ran a HijackThis scan,and as far as i can see i have only one uncertain file that i don't know. Got annoying popups on IE,so i downloaded HjT and figured i'd give it a try. 2-3 popups came up every time messenger was used. Other than that all was good. Protection gear i use is: BPS,Nod32 and Windows defender...still:-(

Well enough said. Here's the HjT log (can someone help me with it?
My bet is on the 04-HKLM file tagged: BLAHINTRAMFCDDART)

Logfile of HijackThis v1.99.1
Scan saved at 23:31:45, on 01.03.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\XP\System32\smss.exe
C:\XP\system32\winlogon.exe
C:\XP\system32\services.exe
C:\XP\system32\lsass.exe
C:\XP\system32\Ati2evxx.exe
C:\XP\system32\svchost.exe
C:\Programs\Windows Defender\MsMpEng.exe
C:\XP\System32\svchost.exe
C:\XP\system32\spoolsv.exe
C:\Programs\Eset\nod32krn.exe
C:\XP\system32\svchost.exe
C:\XP\system32\Ati2evxx.exe
C:\XP\Explorer.EXE
C:\Programs\DAEMON Tools\daemon.exe
C:\Programs\Java\jre1.5.0_11\bin\jusched.exe
C:\XP\SOUNDMAN.EXE
C:\Programs\Eset\nod32kui.exe
C:\Programs\Windows Defender\MSASCui.exe
C:\XP\system32\ctfmon.exe
C:\Programs\Internet Explorer\iexplore.exe
c:\programs\intern~1\iexplore.exe
C:\Programs\MSN Messenger\usnsvc.exe
C:\Programs\BulletProofSoft.com\BPS Spyware Remover\SpyRem.exe
C:\Profiles\Admin\Desktop\HijackThis.exe
C:\Programs\Mozilla Firefox\firefox.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programs\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programs\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programs\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programs\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Programs\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Programs\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [WinampAgent] C:\Programs\Winamp\winampa.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programs\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [BLAHINTRAMFCDDART] C:\Profiles\All Users\Application Data\dash spam blah intra\wave part.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Programs\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\XP\system32\ctfmon.exe
O4 - HKCU\..\Run: [INTRACLOCK] C:\Profiles\Admin\APPLIC~1\MEMO64~1\mfcd that.exe
O4 - HKCU\..\Run: [BPS Spyware Remover] C:\Programs\BulletProofSoft.com\BPS Spyware Remover\SpyRem.exe
O4 - Startup: Adobe Gamma.lnk = C:\Programs\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programs\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programs\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programs\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: @C:\Programs\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programs\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Programs\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programs\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://roaddog.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {A243F6C2-34D2-4549-BCCD-A7BEF759B236} (Seekford Solutions, Inc.'s ssiPictureUploader Control) - http://img.funtigo.com/images/uploader/ssiPictureUploader.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{06A55F8D-7C6F-4B4D-9EAD-DF1067A542C0}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{06A55F8D-7C6F-4B4D-9EAD-DF1067A542C0}: NameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{06A55F8D-7C6F-4B4D-9EAD-DF1067A542C0}: NameServer = 192.168.1.1
O17 - HKLM\System\CS3\Services\Tcpip\..\{06A55F8D-7C6F-4B4D-9EAD-DF1067A542C0}: NameServer = 192.168.1.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Programs\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Programs\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programs\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\XP\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\XP\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programs\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: License Management Service ESD - element5 - C:\Programs\Common Files\element5 Shared\Service\Licence Manager ESD.exe
O23 - Service: NBService - Nero AG - C:\Programs\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Programs\Eset\nod32krn.exe
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 1,075 • Replies: 2
No top replies

 
timberlandko
 
  1  
Reply Thu 1 Mar, 2007 07:04 pm
You've got a few things going on there, and likely a few more HJT doesn't show.

First thing I'd recommend is that you get rid of BPS and all related files and folders - it is a known ROGUE PRODUCT - not the sorta thing thats gonna do you any good at all.

Once that's done, start with the steps listed HERE, save the resulting logs/reports, and post them to this thread.

Pay attention in particular to the instructions regarding HijackThis - You don't need to uninstall your version, but move it off your desktop and put it into a folder of its own, either in your Programs folder or directly on your root drive, as detailed, and when you run HJT the next time, as the final step after completing that other stuff, run it with no browsers, email, or chat/messaging clients running.
0 Replies
 
roaddog
 
  1  
Reply Fri 2 Mar, 2007 05:31 am
tnx
ok...i see that there's a lot to learn after all:-)
Well...i'll run through the steps and report back (may not be today,but i'll be back)
Thank you so much...:-)
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » Just to be certain regarding use of HijackThis
Copyright © 2024 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.03 seconds on 04/25/2024 at 08:41:29