Thanks nathan jardine the program helped me find and repair the hijacker parasite.
Main Topics
Browse All TopicsI have a old pentium two ibm thinkpad laptop. The machine is running as slow as a snail. It had a porno web browser installed on it that had an icon on the desktop called webcam. When you clicked on it a broswer plugin would run from some website called nasty blondes. I uninstalled the web browser and ran iefix tool and the lspfix tool . Now Internet explorer will find other websights and so on but the machine is still lugged down to a crawl. I ran hijack this and this is the log . Logfile of HijackThis v1.98.0
Scan saved at 8:51:52 PM, on 8/16/2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\System32\ibmpms
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\WINDOWS\System32\ati2ev
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\system32\regsvc
C:\WINDOWS\system32\MSTask
C:\WINDOWS\System32\WBEM\W
C:\WINDOWS\System32\mspmsp
C:\WINDOWS\system32\svchos
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\MsgSys
C:\WINDOWS\System32\tp4mon
C:\WINDOWS\System32\ltcm00
C:\WINDOWS\System32\Promon
C:\WINDOWS\System32\ibmpms
C:\Program Files\NavNT\vptray.exe
C:\WINDOWS\System32\Atipta
C:\Program Files\Common Files\CMEII\CMESys.exe
C:\Program Files\Common Files\Real\Update_OB\reals
C:\PROGRA~1\COMETS~1\DM\bi
C:\windows\180solutions\ms
C:\WINDOWS\System32\3W5QUT
C:\Program Files\Common Files\GMT\GMT.exe
C:\WINDOWS\system32\LxrSG2
C:\WINDOWS\System32\LxrCon
E:\antivirus\hijack this\HijackThis.exe
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R0 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-0
O2 - BHO: (no name) - {7B55BB05-0B4D-44fd-81A6-B
O2 - BHO: E.HH - {9E992732-295F-4987-8BE3-1
O2 - BHO: CSBHO - {D14D6793-9B65-11D3-80B6-0
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
O3 - Toolbar: My &Search Bar - {014DA6C9-189F-421a-88CD-0
O3 - Toolbar: Starware - {FE6BC4EF-5676-484B-88AE-8
O4 - HKLM\..\Run: [TrackPointSrv] tp4mon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [XircWinModem4] ltcm000c.exe 9
O4 - HKLM\..\Run: [Promon.exe] Promon.exe
O4 - HKLM\..\Run: [IBMPMSVC] %SystemRoot%\System32\ibmp
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
O4 - HKLM\..\Run: [DM_Server] C:\PROGRA~1\COMETS~1\DM\bi
O4 - HKLM\..\Run: [APIMon] C:\WINDOWS\System32\wspool
O4 - HKLM\..\Run: [msbb] c:\windows\180solutions\ms
O4 - HKLM\..\Run: [srcxsrkn] C:\WINDOWS\srcxsrkn.exe
O4 - HKCU\..\Run: [EZNXP] C:\PROGRA~1\EZN\EVERYO~1\e
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weath
O4 - HKCU\..\Run: [NortonAV] C:\WINDOWS\System32\3W5QUT
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe
O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\Precis
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-0
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-0
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B
O16 - DPF: {11111111-1111-1111-1111-1
O16 - DPF: {1678F7E1-C422-11D0-AD7D-0
O16 - DPF: {2B323CD9-50E3-11D3-9466-0
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-C
O16 - DPF: {41F17733-B041-4099-A042-B
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-0
O16 - DPF: {946B0485-8F8C-4C35-A6E7-D
O16 - DPF: {A45F39DC-3608-4237-8F0E-1
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-5
O16 - DPF: {D18F962A-3722-4B59-B08D-2
O16 - DPF: {DA9A0B1E-9B7B-11D3-B8A4-0
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-5
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R0 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-0
O2 - BHO: (no name) - {7B55BB05-0B4D-44fd-81A6-B
O2 - BHO: E.HH - {9E992732-295F-4987-8BE3-1
O2 - BHO: CSBHO - {D14D6793-9B65-11D3-80B6-0
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
O3 - Toolbar: My &Search Bar - {014DA6C9-189F-421a-88CD-0
O3 - Toolbar: Starware - {FE6BC4EF-5676-484B-88AE-8
O4 - HKLM\..\Run: [TrackPointSrv] tp4mon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [XircWinModem4] ltcm000c.exe 9
O4 - HKLM\..\Run: [Promon.exe] Promon.exe
O4 - HKLM\..\Run: [IBMPMSVC] %SystemRoot%\System32\ibmp
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
O4 - HKLM\..\Run: [DM_Server] C:\PROGRA~1\COMETS~1\DM\bi
O4 - HKLM\..\Run: [APIMon] C:\WINDOWS\System32\wspool
O4 - HKLM\..\Run: [msbb] c:\windows\180solutions\ms
O4 - HKLM\..\Run: [srcxsrkn] C:\WINDOWS\srcxsrkn.exe
O4 - HKCU\..\Run: [EZNXP] C:\PROGRA~1\EZN\EVERYO~1\e
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weath
O4 - HKCU\..\Run: [NortonAV] C:\WINDOWS\System32\3W5QUT
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe
O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\Precis
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-0
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-0
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B
O16 - DPF: {11111111-1111-1111-1111-1
O16 - DPF: {1678F7E1-C422-11D0-AD7D-0
O16 - DPF: {2B323CD9-50E3-11D3-9466-0
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-C
O16 - DPF: {41F17733-B041-4099-A042-B
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-0
O16 - DPF: {946B0485-8F8C-4C35-A6E7-D
O16 - DPF: {A45F39DC-3608-4237-8F0E-1
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-5
O16 - DPF: {D18F962A-3722-4B59-B08D-2
O16 - DPF: {DA9A0B1E-9B7B-11D3-B8A4-0
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-5
would appreciate some help in spotting the malware that might be on this machine. ezminer
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Business Accounts
Answer for Membership
by: nathan_jardinePosted on 2004-08-17 at 09:32:16ID: 11822334
An easier way might be to install this program which is free and it should find the problem. It's about the best out there for free and I have never see where it did not pick up the spyware.
nloads/fil e_descript ion/ 0,fid, 22262,00.a sp
http://www.pcworld.com/dow