Posted: 2004-12-15 03:43pm
Thank you!
Get your fill of sci-fi, science, and mockery of stupid ideas
http://bbs.stardestroyer.net/
Logfile of HijackThis v1.99.0
Scan saved at 10:43:24 PM, on 23/12/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\3WEB ACCESS MANAGER\ACCESS MANAGER\APP\ENTERNET.EXE
C:\WINDOWS\WUAUCLT.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\SPYBOTSD.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [WinTools] C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
O4 - HKLM\..\RunServices: [WinTools] C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE
This site (also listed in the C&G FAQ) has a list of all HijackThis! mirrors. Spyware sometimes blocks it, though, so here is a direct link to one of the mirrors. By the way, 1.99, a new version, is out -- everyone be sure to snag it. Keep a copy of 1.98.2, though, as 1.99 is known to trigger crashes in certain r00ted systems.Stormbringer wrote:Where the heck do I download Hijack This?
Logfile of HijackThis v1.99.0
Scan saved at 01:10:20, on 12/26/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\wanmpsvc.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\TrayBar\Traybar.exe
D:\Program Files\Real\RealPlayer\RealPlay.exe
D:\WINDOWS\StartupMonitor.exe
D:\WINDOWS\System32\RunDll32.exe
D:\Program Files\Restore Desktop\RestoreDesktop.exe
D:\Program Files\Calculadora Printing Calculator\calc246.exe
D:\Program Files\Hidden Menu\HiddenMenu.exe
D:\PROGRA~1\FOLDER~3\folders.exe
D:\Program Files\Unforgiven Organizer\unage.exe
D:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
D:\Program Files\TurboNote\tbnote.exe
D:\Program Files\Birthday\Birthday.exe
D:\Program Files\Rainlendar\Rainlendar.exe
D:\Program Files\SaverStarter\SaverStarter.exe
D:\Program Files\TrayBar\Traybar.exe
D:\WINDOWS\System32\wuauclt.exe
D:\Program Files\CompuServe 7.0\wcs2000.exe
D:\WINDOWS\Explorer.EXE
G:\FireFox\firefox.exe
D:\PROGRA~1\ULTIMA~1.7\uzip.exe
D:\DOCUME~1\DANICO~1\LOCALS~1\TEMP\HIJACKTHIS.EXE
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Traybar] D:\Program Files\TrayBar\Traybar.exe
O4 - HKLM\..\Run: [RealTray] D:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKCU\..\Run: [RestoreDesktop] D:\Program Files\Restore Desktop\RestoreDesktop.exe
O4 - HKCU\..\Run: [CalcIntel] D:\Program Files\Calculadora Printing Calculator\calc246.exe systray
O4 - HKCU\..\Run: [Hidden Menu] D:\Program Files\Hidden Menu\HiddenMenu.exe
O4 - HKCU\..\Run: [Folders (1.00)] "D:\PROGRA~1\FOLDER~3\folders.exe" t
O4 - HKCU\..\Run: [U32 Agent] "D:\Program Files\Unforgiven Organizer\unage.exe"
O4 - HKCU\..\Run: [EMA] D:\Program Files\EMA\EMA.exe start
O4 - Startup: Birthday.lnk = D:\Program Files\Birthday\Birthday.exe
O4 - Startup: FreeShade.lnk = D:\WINDOWS\FreeShade.exe
O4 - Startup: MiniReminder.lnk = D:\Program Files\MiniReminder\MiniReminder.exe
O4 - Startup: Rainlendar.lnk = D:\Program Files\Rainlendar\Rainlendar.exe
O4 - Startup: ScreenSaverStarter.exe.lnk = D:\Program Files\SaverStarter\SaverStarter.exe
O4 - Startup: Traybar.lnk = D:\Program Files\TrayBar\Traybar.exe
O4 - Global Startup: CompuServe 7.0 Tray Icon.lnk = D:\Program Files\CompuServe 7.0\cstray.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: TurboNote.lnk = D:\Program Files\TurboNote\tbnote.exe
O8 - Extra context menu item: Save Image - res://D:\Program Files\Picture Ace Lite\PictureAceLite.exe/130
O8 - Extra context menu item: Send Link to TrekTrak - D:\WINDOWS\Web\TrekTrakLink.htm
O8 - Extra context menu item: Send Page to TrekTrak - D:\WINDOWS\Web\TrekTrak.htm
O8 - Extra context menu item: Sothink SWF Catcher - D:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Insert signature - {5E35CA41-3800-4ce7-843A-967B4D761700} - D:\Program Files\Quotes\ieplugin\ieplugin.exe
O9 - Extra button: (no name) - {5E35CA41-3800-4ce7-843A-967B4D761701} - D:\Program Files\Quotes\ieplugin\launch.htm
O9 - Extra 'Tools' menuitem: Quotes plugin - QLiner.com - {5E35CA41-3800-4ce7-843A-967B4D761701} - D:\Program Files\Quotes\ieplugin\launch.htm
O9 - Extra button: CachePal - {5F4A4622-8370-440e-88CC-CA2256D1A08A} - D:\WINDOWS\System32\cachepal.exe
O9 - Extra 'Tools' menuitem: CachePal - {5F4A4622-8370-440e-88CC-CA2256D1A08A} - D:\WINDOWS\System32\cachepal.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - D:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Flash Movie Extractor Scout LITE - {D5FA3931-9170-4C51-9053-4C64B11CE531} - D:\Program Files\Flash Movie Extractor Scout LITE\flashextract.exe
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - D:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - D:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {BC8FABCD-8649-4eef-89DB-C012144ADFB1} - D:\Program Files\Picture Ace Lite\PictureAceLite.exe (HKCU)
O9 - Extra 'Tools' menuitem: Picture Ace Lite - {BC8FABCD-8649-4eef-89DB-C012144ADFB1} - D:\Program Files\Picture Ace Lite\PictureAceLite.exe (HKCU)
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/fu ... .0.0.8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v ... 3242102312
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/sho ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{94EA6AE5-744C-4E80-AE58-A7F52BA81AFB}: NameServer = 205.188.146.145
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\System32\HPZipm12.exe
O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - D:\WINDOWS\wanmpsvc.exe
CursorMania is a program that tries to load up CoolWebSearch at every opportunity, but I see no trace of CWS in this log (presumably killed by whatever automated programs you've used). Best to kill the entry and do another sweep with CWShredder to be on the safe side.O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/fu ... .0.0.8.cab
The following are optional:R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV Media\TvmBho.dll
O2 - BHO: (no name) - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - (no file)
O4 - HKLM\..\Run: [zSearch] C:\Program Files\zSearch\Zstb.exe
O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\Run: [msmc] C:\WINDOWS\system32\msmc.exe
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - Startup: PowerReg Scheduler.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
I have the latest version because when I ran the update it said i had the most up-to-date version.Crayz9000 wrote:Make *sure* you have the latest CWS Shredder. Older versions will be noticed by CWS and won't run.
Yeah, i have been running it in safe mode and it clears everything out just fine. But when I get back into windows normally....everything comes back. However the exe changes names every time.Datana wrote:jcow79: Have you killed infected background processes before starting the HJT! purge? From what I can see, C:\WINNT\system32\vqugor.exe is likely what's restoring the deleted entries, and if it's doing something while HJT! is running, it won't get removed. Apart from that, I can't see anything else suspicious in that log. Try Kill2Me as well -- you appear to have Look2Me, judging by the presence of links to 69.20.16.183.