I have a old pentium two ibm thinkpad laptop. The machine is running as slow as a snail. It had a porno web browser installed on it that had an icon on the desktop called webcam. When you clicked on it a broswer plugin would run from some website called nasty blondes. I uninstalled the web browser and ran iefix tool and the lspfix tool . Now Internet explorer will find other websights and so on but the machine is still lugged down to a crawl. I ran hijack this and this is the log . Logfile of HijackThis v1.98.0
Scan saved at 8:51:52 PM, on 8/16/2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\System32\ibmpms
vc.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\System32\ati2ev
xx.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\system32\regsvc
.exe
C:\WINDOWS\system32\MSTask
.exe
C:\WINDOWS\System32\WBEM\W
inMgmt.exe
C:\WINDOWS\System32\mspmsp
sv.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\MsgSys
.EXE
C:\WINDOWS\System32\tp4mon
.exe
C:\WINDOWS\System32\ltcm00
0c.exe
C:\WINDOWS\System32\Promon
.exe
C:\WINDOWS\System32\ibmpms
vc.exe
C:\Program Files\NavNT\vptray.exe
C:\WINDOWS\System32\Atipta
xx.exe
C:\Program Files\Common Files\CMEII\CMESys.exe
C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe
C:\PROGRA~1\COMETS~1\DM\bi
n\dmserver
.exe
C:\windows\180solutions\ms
bb.exe
C:\WINDOWS\System32\3W5QUT
2U.exe
C:\Program Files\Common Files\GMT\GMT.exe
C:\WINDOWS\system32\LxrSG2
0s.exe
C:\WINDOWS\System32\LxrCon
fig.exe
E:\antivirus\hijack this\HijackThis.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://www.eznsearch.comR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://www.eznsearch.comR0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.ev1.net/R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://www.ev1.netR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydial/*http://www.yahoo.comR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydial/*http://www.yahoo.com/search/ie.htmlR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://www.eznsearch.comR0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://yahoo.sbc.com/dialR0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
http://files.cc.cometsystems.com/assist/cc/1.0/1A/assist.htmlR0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
R1 - HKCU\Software\Microsoft\In
ternet Explorer\SearchURL,(Defaul
t) =
http://www.eznsearch.comR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,First Home Page =
http://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update&O1=b1R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.ht
m
O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-0
7CFE51CFF1
0} - C:\Program Files\MySearch\bar\1.bin\S
4BAR.DLL
O2 - BHO: (no name) - {7B55BB05-0B4D-44fd-81A6-B
136188F5DE
B} - C:\WINDOWS\questmod-1.dll
O2 - BHO: E.HH - {9E992732-295F-4987-8BE3-1
6FAC163919
8} - C:\DOCUME~1\ALLUSE~1\APPLI
C~1\IESERV
~1\IEServi
ce.dll
O2 - BHO: CSBHO - {D14D6793-9B65-11D3-80B6-0
0500487BDB
A} - C:\PROGRA~1\COMETS~1\Platf
orm\Bin\cs
bho.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: My &Search Bar - {014DA6C9-189F-421a-88CD-0
7CFE51CFF1
0} - C:\Program Files\MySearch\bar\1.bin\S
4BAR.DLL
O3 - Toolbar: Starware - {FE6BC4EF-5676-484B-88AE-8
8332391325
6} - C:\PROGRA~1\COMETS~1\Platf
orm\Bin\cs
ietb.dll
O4 - HKLM\..\Run: [TrackPointSrv] tp4mon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [XircWinModem4] ltcm000c.exe 9
O4 - HKLM\..\Run: [Promon.exe] Promon.exe
O4 - HKLM\..\Run: [IBMPMSVC] %SystemRoot%\System32\ibmp
msvc.exe -helper
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [DM_Server] C:\PROGRA~1\COMETS~1\DM\bi
n\dmserver
.exe /onreboot
O4 - HKLM\..\Run: [APIMon] C:\WINDOWS\System32\wspool
s.exe
O4 - HKLM\..\Run: [msbb] c:\windows\180solutions\ms
bb.exe
O4 - HKLM\..\Run: [srcxsrkn] C:\WINDOWS\srcxsrkn.exe
O4 - HKCU\..\Run: [EZNXP] C:\PROGRA~1\EZN\EVERYO~1\e
znorun.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weath
er.exe 1
O4 - HKCU\..\Run: [NortonAV] C:\WINDOWS\System32\3W5QUT
2U.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe
O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\Precis
ionTime.ex
e
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict
.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch
.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-0
0aa003c157
a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-0
0aa003c157
a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
0C0F0318AF
E} - C:\WINDOWS\System32\Shdocv
w.dll
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B
7D41EF1CB5
2} - C:\Program Files\AWS\WeatherBug\Weath
er.exe (HKCU)
O16 - DPF: {11111111-1111-1111-1111-1
1111111111
1} -
http://usa-download.nocreditcard.com/download/newdial-erp/2656/dialer.exeO16 - DPF: {1678F7E1-C422-11D0-AD7D-0
0400515CAA
A} (CometCursor Class) -
http://files.cometsystems.com/cometcursor/cobrand/comet.cab?0.52562137026477731082167305254O16 - DPF: {2B323CD9-50E3-11D3-9466-0
0A0C970049
8} (Yahoo! Audio Conferencing) -
http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cabO16 - DPF: {2B96D5CC-C5B5-49A5-A69D-C
C0A30F9028
C} (MiniBugTransporterX Class) -
http://download.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?O16 - DPF: {41F17733-B041-4099-A042-B
518BB6A408
C} -
http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exeO16 - DPF: {56336BCB-3D8A-11D6-A00B-0
050DA18DE7
1} (RdxIE Class) -
http://207.188.7.150/09fe16767d6772eb0217/netzip/RdxIE601.cabO16 - DPF: {7D1E9C49-BD6A-11D3-87A8-0
09027A35D7
3} (Yahoo! Audio UI1) -
http://chat.yahoo.com/cab/yacsui.cabO16 - DPF: {946B0485-8F8C-4C35-A6E7-D
2115E3B0B4
F} (HTMLAccess Class) -
http://usa-download.nocreditcard.com/download/Object/DialerHTML/DHTMLAccess1040.cabO16 - DPF: {A45F39DC-3608-4237-8F0E-1
39F1BC4946
4} -
http://php.offshoreclicks.com/dialup_files/99950599.cabO16 - DPF: {AD7FAFB0-16D6-40C3-AF27-5
85D6E6453F
D} (loader Class) -
http://dload.ipbill.com/del/loader.cabO16 - DPF: {D18F962A-3722-4B59-B08D-2
8BB9EB2281
E} -
http://photos.yahoo.com/ocx/us/yexplorer1_9us.cabO16 - DPF: {DA9A0B1E-9B7B-11D3-B8A4-0
0C04F79641
C} (NSUpdateLiteCtrl Class) -
http://204.177.92.201/quickdl/action/NSupd9x.cabO16 - DPF: {F58E1CEF-A068-4C15-BA5E-5
87CAF3EE8C
6} (MSN Chat Control 4.5) -
http://fdl.msn.com/public/chat/msnchat45.cabR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://www.eznsearch.comR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://www.eznsearch.comR0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.ev1.net/R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://www.ev1.netR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydial/*http://www.yahoo.comR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydial/*http://www.yahoo.com/search/ie.htmlR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://www.eznsearch.comR0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://yahoo.sbc.com/dialR0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
http://files.cc.cometsystems.com/assist/cc/1.0/1A/assist.htmlR0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
R1 - HKCU\Software\Microsoft\In
ternet Explorer\SearchURL,(Defaul
t) =
http://www.eznsearch.comR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,First Home Page =
http://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update&O1=b1R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.ht
m
O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-0
7CFE51CFF1
0} - C:\Program Files\MySearch\bar\1.bin\S
4BAR.DLL
O2 - BHO: (no name) - {7B55BB05-0B4D-44fd-81A6-B
136188F5DE
B} - C:\WINDOWS\questmod-1.dll
O2 - BHO: E.HH - {9E992732-295F-4987-8BE3-1
6FAC163919
8} - C:\DOCUME~1\ALLUSE~1\APPLI
C~1\IESERV
~1\IEServi
ce.dll
O2 - BHO: CSBHO - {D14D6793-9B65-11D3-80B6-0
0500487BDB
A} - C:\PROGRA~1\COMETS~1\Platf
orm\Bin\cs
bho.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: My &Search Bar - {014DA6C9-189F-421a-88CD-0
7CFE51CFF1
0} - C:\Program Files\MySearch\bar\1.bin\S
4BAR.DLL
O3 - Toolbar: Starware - {FE6BC4EF-5676-484B-88AE-8
8332391325
6} - C:\PROGRA~1\COMETS~1\Platf
orm\Bin\cs
ietb.dll
O4 - HKLM\..\Run: [TrackPointSrv] tp4mon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [XircWinModem4] ltcm000c.exe 9
O4 - HKLM\..\Run: [Promon.exe] Promon.exe
O4 - HKLM\..\Run: [IBMPMSVC] %SystemRoot%\System32\ibmp
msvc.exe -helper
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [DM_Server] C:\PROGRA~1\COMETS~1\DM\bi
n\dmserver
.exe /onreboot
O4 - HKLM\..\Run: [APIMon] C:\WINDOWS\System32\wspool
s.exe
O4 - HKLM\..\Run: [msbb] c:\windows\180solutions\ms
bb.exe
O4 - HKLM\..\Run: [srcxsrkn] C:\WINDOWS\srcxsrkn.exe
O4 - HKCU\..\Run: [EZNXP] C:\PROGRA~1\EZN\EVERYO~1\e
znorun.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weath
er.exe 1
O4 - HKCU\..\Run: [NortonAV] C:\WINDOWS\System32\3W5QUT
2U.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe
O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\Precis
ionTime.ex
e
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict
.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch
.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-0
0aa003c157
a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-0
0aa003c157
a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
0C0F0318AF
E} - C:\WINDOWS\System32\Shdocv
w.dll
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B
7D41EF1CB5
2} - C:\Program Files\AWS\WeatherBug\Weath
er.exe (HKCU)
O16 - DPF: {11111111-1111-1111-1111-1
1111111111
1} -
http://usa-download.nocreditcard.com/download/newdial-erp/2656/dialer.exeO16 - DPF: {1678F7E1-C422-11D0-AD7D-0
0400515CAA
A} (CometCursor Class) -
http://files.cometsystems.com/cometcursor/cobrand/comet.cab?0.52562137026477731082167305254O16 - DPF: {2B323CD9-50E3-11D3-9466-0
0A0C970049
8} (Yahoo! Audio Conferencing) -
http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cabO16 - DPF: {2B96D5CC-C5B5-49A5-A69D-C
C0A30F9028
C} (MiniBugTransporterX Class) -
http://download.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?O16 - DPF: {41F17733-B041-4099-A042-B
518BB6A408
C} -
http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exeO16 - DPF: {56336BCB-3D8A-11D6-A00B-0
050DA18DE7
1} (RdxIE Class) -
http://207.188.7.150/09fe16767d6772eb0217/netzip/RdxIE601.cabO16 - DPF: {7D1E9C49-BD6A-11D3-87A8-0
09027A35D7
3} (Yahoo! Audio UI1) -
http://chat.yahoo.com/cab/yacsui.cabO16 - DPF: {946B0485-8F8C-4C35-A6E7-D
2115E3B0B4
F} (HTMLAccess Class) -
http://usa-download.nocreditcard.com/download/Object/DialerHTML/DHTMLAccess1040.cabO16 - DPF: {A45F39DC-3608-4237-8F0E-1
39F1BC4946
4} -
http://php.offshoreclicks.com/dialup_files/99950599.cabO16 - DPF: {AD7FAFB0-16D6-40C3-AF27-5
85D6E6453F
D} (loader Class) -
http://dload.ipbill.com/del/loader.cabO16 - DPF: {D18F962A-3722-4B59-B08D-2
8BB9EB2281
E} -
http://photos.yahoo.com/ocx/us/yexplorer1_9us.cabO16 - DPF: {DA9A0B1E-9B7B-11D3-B8A4-0
0C04F79641
C} (NSUpdateLiteCtrl Class) -
http://204.177.92.201/quickdl/action/NSupd9x.cabO16 - DPF: {F58E1CEF-A068-4C15-BA5E-5
87CAF3EE8C
6} (MSN Chat Control 4.5) -
http://fdl.msn.com/public/chat/msnchat45.cabwould appreciate some help in spotting the malware that might be on this machine. ezminer