Note that I killed strun, so it won't show up in this log as a running process:
Logfile of HijackThis v1.97.5
Scan saved at 7:37:21 PM, on 2/28/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\csrss.
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\System32\PGPsdk
C:\WINDOWS\System32\svchos
C:\Program Files\Harakan Software\VNC\WinVNC.exe
C:\WINDOWS\Explorer2.exe
C:\Program Files\Softick\PPP\Bin\PPPG
C:\Program Files\PGP Corporation\PGP for Windows XP\PGPtray.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\Microsoft Office\Office\POWERPNT.EXE
C:\WINDOWS\msagent\AgentSv
C:\Program Files\Opera7\opera.exe
C:\Program Files\AIM\aim.exe
C:\PROGRA~1\WINZIP\winzip3
C:\Documents and Settings\chris\Local Settings\Temp\HijackThis.e
F0 - system.ini: Shell=Explorer2.exe
F2 - REG:system.ini: Shell=Explorer2.exe
O2 - BHO: Firepad FireConverter - {6427806D-3820-11D5-9939-0
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCh
O4 - HKLM\..\Run: [SoftickPPP] "C:\Program Files\Softick\PPP\Bin\PPPG
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\Harakan Software\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.ex
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: PGPtray.lnk = ?
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O16 - DPF: {33564D57-0000-0010-8000-0
O16 - DPF: {9F1C11AA-197B-4942-BA54-4
O17 - HKLM\System\CCS\Services\T
Main Topics
Browse All Topics





by: sirbountyPosted on 2004-02-28 at 16:03:39ID: 10478110
To be sure use more than one of each of these...
king.org/ ut.com/lib rary/blfre espyware.h tm om/program /hijackthi s.html com/~merij n/ cwschron icles.html #cwshredde r
om/sscv6/d efault.asp ? productid =symhome&l angid=ie&v enid=sym .com/house call/start _corp.asp om/actives can/ mfs/defaul t.asp emotevirus chk.html
hcd/VB_Pro jects/Wins ockFix.zip
Check for Spyware:
Spybot-S&D -->http://www.safer-networ
Ad-Aware --> http://www.netsecurity.abo
HijackThis -->http://www.spychecker.c
Web Shredder -->http://www.spywareinfo.
Check for Viruses with online scanners:
Norton/Symantec --> http://security.symantec.c
Trend Micro --> http://housecall.antivirus
Panda ActiveScan --> http://www.pandasoftware.c
McAfee Security --> http://us.mcafee.com/root/
Individual File Scanner --> http://www.kaspersky.com/r
Post the Hijackthis log for further review.
You might also try repairing winsock using this:
http://members.shaw.ca/tec