PDA

View Full Version : Thiri's Hijack Log...new thread


Thiri
08-07-2003, 06:24 PM
Greetings. This is not exactly a reply, it's a request for help.
Running W2000 on a P3 600. I seem to get locked into a window - running, say, my browser. The Windows taskbar (on Autohide) will not show up, nor will programs which have shortcut keys. I can get out of this by presing Ctrl+Alt+Del to pull up the Windows Task Mngr - that is enough, dont need to end any task.
Here is a log from Hijack This:
Logfile of HijackThis v1.96.0
Scan saved at 2:34:05 AM, on 08-Aug-03
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
E:\WINNT\System32\smss.exe
E:\WINNT\system32\winlogon.exe
E:\WINNT\system32\services.exe
E:\WINNT\system32\lsass.exe
C:\Program Files\Sygate Personal Firewall\Smc.exe
E:\WINNT\system32\svchost.exe
E:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\AVG6\FRESHA~1\avgserv.exe
E:\WINNT\System32\CTsvcCDA.exe
C:\Program Files\DAP\DKService.exe
E:\WINNT\System32\svchost.exe
E:\WINNT\system32\regsvc.exe
E:\WINNT\system32\MSTask.exe
E:\WINNT\system32\stisvc.exe
E:\WINNT\System32\WBEM\WinMgmt.exe
E:\WINNT\System32\mspmspsv.exe
E:\WINNT\system32\svchost.exe
E:\WINNT\Explorer.EXE
E:\WINNT\system32\devldr32.exe
C:\PROGRA~1\AVG6\FRESHA~1\avgcc32.exe
E:\Program Files\Dual Wheel Mouse\4DMAIN.EXE
E:\WINNT\StartupMonitor.exe
C:\Program Files\PostCast Server\postcastserver.exe
E:\WINNT\system32\internat.exe
C:\Program Files\Speaking Clock\Speaking Clock Deluxe\SpClDlx.exe
C:\Program Files\Clipomatic 2_01\Clipomatic.exe
C:\Program Files\WIRM1021\WIRM.EXE
C:\Program Files\Strokeit9_2a\strokeit.exe
C:\Program Files\Folder Cache\ffolder.exe
C:\Program Files\LeechGet\LeechGet 2002\LeechGet.exe
E:\Program Files\INS\VitalAgent\Program\VtlAgent.exe
C:\Program Files\band\Bandwidth Monitor\Bandwidth Monitor.exe
C:\Program Files\PopTray30B5\PopTray.exe
C:\ProgramFiles2\Katmouse\KatMouse.exe
C:\ProgramFiles2\vcomm\PDExplo.exe
E:\WINNT\System32\svchost.exe
C:\Program Files\Avant Browser 8 Beta\abrowser.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\Program Files\Treepad 2.8\Treepad.exe
E:\WINNT\system32\taskmgr.exe
E:\DOCUME~1\thiri1\LOCALS~1\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = E:\WINNT\System32\blank.htm
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - E:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\acrobat\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Popup Manager - {08E74C67-99A6-45C7-94DA-A397A8FD8082} - C:\Program Files\Popup Manager\PopupMgr_1.0.0.7.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O2 - BHO: (no name) - {9A23B8A4-C6C9-4A68-8FA6-5F905DC8FF80} - C:\Program Files\Internet Eraser\PKExt.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - e:\winnt\googletoolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - e:\winnt\googletoolbar.dll
O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - E:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\AVG6\FRESHA~1\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [Jet Detection] C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [Disc Detector] E:\Program Files\Creative\ShareDLL\ctnotify.exe
O4 - HKLM\..\Run: [WheelMouse] E:\Program Files\Dual Wheel Mouse\4DMAIN.EXE
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\SYGATE~1\Smc.exe -startgui
O4 - HKLM\..\Run: [PostCast Server] C:\Program Files\PostCast Server\postcastserver.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [Speaking Clock Deluxe] "C:\Program Files\Speaking Clock\Speaking Clock Deluxe\SpClDlx.exe"
O4 - Startup: Bandwidth Monitor.lnk = C:\Program Files\band\Bandwidth Monitor\Bandwidth Monitor.exe
O4 - Startup: PopTray.lnk = C:\Program Files\PopTray30B5\PopTray.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Startup: KatMouse.lnk = C:\ProgramFiles2\Katmouse\KatMouse.exe
O4 - User Startup: Bandwidth Monitor.lnk = C:\Program Files\band\Bandwidth Monitor\Bandwidth Monitor.exe
O4 - User Startup: PopTray.lnk = C:\Program Files\PopTray30B5\PopTray.exe
O4 - User Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - User Startup: KatMouse.lnk = C:\ProgramFiles2\Katmouse\KatMouse.exe
O4 - Global Startup: MyVitalAgent.lnk = E:\Program Files\INS\VitalAgent\Program\VtlAgent.exe
O8 - Extra context menu item: &Google Search - res://E:\WINNT\GoogleToolbar.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://E:\WINNT\GoogleToolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://E:\WINNT\GoogleToolbar.dll/cmcache.html
O8 - Extra context menu item: Customize &Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download using LeechGet - file://C:\Program Files\LeechGet\LeechGet 2002\\AddUrl.html
O8 - Extra context menu item: Download using LeechGet Wizard - file://C:\Program Files\LeechGet\LeechGet 2002\\Wizard.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms &] - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: IEB: Frame: Open in &New Window - C:\Program Files\IE Booster\frame-open-in-new-window.html
O8 - Extra context menu item: IEB: Frame: Open in &This Window - C:\Program Files\IE Booster\frame-open-in-this-window.html
O8 - Extra context menu item: IEB: Image: Copy Path to Clipboard - C:\Program Files\IE Booster\image-copy-path-to-clipboard.html
O8 - Extra context menu item: IEB: Image: Show Image Data - C:\Program Files\IE Booster\image-view-image-data.html
O8 - Extra context menu item: IEB: Link: Copy as <A href="URL">caption</A> - C:\Program Files\IE Booster\link-copy.html
O8 - Extra context menu item: IEB: Link: Open in New Minimized Window - C:\Program Files\IE Booster\link-open-minimized.html
O8 - Extra context menu item: IEB: Selection: Copy as plain text - C:\Program Files\IE Booster\selection-copy-plaintext.html
O8 - Extra context menu item: IEB: Selection: Open in Browser - C:\Program Files\IE Booster\selection-open-in-browser.html
O8 - Extra context menu item: IEB: Selection: Show Partial Source - C:\Program Files\IE Booster\selection-show-source.html
O8 - Extra context menu item: Parse with LeechGet - file://C:\Program Files\LeechGet\LeechGet 2002\\Parser.html
O8 - Extra context menu item: Save Forms &^ - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Si&milar Pages - res://E:\WINNT\GoogleToolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page - res://E:\WINNT\GoogleToolbar.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Fill Forms (HKLM)
O9 - Extra 'Tools' menuitem: Fill Forms &] (HKLM)
O9 - Extra button: Save (HKLM)
O9 - Extra 'Tools' menuitem: Save Forms &^ (HKLM)
O9 - Extra button: RoboForm (HKLM)
O9 - Extra 'Tools' menuitem: RF Toolbar &2 (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: MUSICMATCH MX Web Player (HKLM)
O9 - Extra button: CuteShield Internet Eraser (HKCU)
O12 - Plugin for .MTD: E:\Program Files\Internet Explorer\Plugins\npmusicn.dll
O12 - Plugin for .spop: E:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {018B7EC3-EECA-11D3-8E71-0000E82C6C0D} - http://www.mp3yes.com/free_mp3_finder.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (sys Class) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} (Google Activate) - http://toolbar.google.com/data/en/deleon/1.1.55-deleon/GoogleNav.cab
O16 - DPF: {6FB9FE59-7D3B-483D-9909-C870BE5AFA1F} (DiskHealth Class) - http://www.pcpitstop.com/pcpitstop/diskhealth.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37582.4637037037
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553528000} - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D81CA86B-EF63-42AF-BEE3-4502D9A03C2D} (MMRadioHostX Class) - http://wwws.musicmatch.com/graphics/WebPlayer/MMLRadio.cab
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - http://officeupdate.microsoft.com/TemplateGallery/downloads/outc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F8E93E81-10A3-462B-A789-1B3454B0923D}: NameServer = 61.0.128.65,61.0.0.5

There seems to be a lot of junk there - what should I delete?

Thanks in advance

mjc
08-07-2003, 07:28 PM
Yeah, there is a lot there.....

Do you really need these connection monitoring tools starting from Startup?
O4 - Startup: Bandwidth Monitor.lnk = C:\Program Files\band\Bandwidth Monitor\Bandwidth Monitor.exe

O4 - User Startup: Bandwidth Monitor.lnk = C:\Program Files\band\Bandwidth Monitor\Bandwidth Monitor.exe

O4 - Global Startup: MyVitalAgent.lnk = E:\Program Files\INS\VitalAgent\Program\VtlAgent.exe

(You should be able to use the programs' options to stop them)

Is this something you installed?

O4 - HKLM\..\Run: [PostCast Server] C:\Program Files\PostCast Server\postcastserver.exe

(any server software is suspect, unless purposefully installed)

Do you need international keyboard support?

O4 - HKCU\..\Run: [internat.exe] internat.exe

(there is a virus that uses this as one of its spoofed names)

A lot of your entries seem to be context menu buttons for IE Booster.....