Hi All,
New to this forum. I have been down for a week due to all sorts of spyware issues. Beleive it or not I tink I solved them.. I hope. But checking in here to make sure. I see a lot of you depend upon hijackthis log files. So.. here is my hijackthis log file.
Please take a look and let me know if there are still things here I should be concerned about. I have had a lot of bugs from trojan horse to Umonitor which I think I just xnayed off of my pc.
I have Spyware Slayer on here now and NIS2005 installed. I;m open to make this thing very rock solid as I do not want to go through what I went through over the past week again.
Logfile of HijackThis v1.99.0
Scan saved at 8:47:26 PM, on 1/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
D:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCE
S.EXE
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\system32\LEXPPS
.EXE
C:\WINDOWS\System32\driver
s\CDAC11BA
.EXE
C:\PROGRA~1\Symantec\NORTO
N~1\GHOSTS
~2.EXE
C:\WINDOWS\System32\hpb2ks
rv.exe
C:\WINDOWS\System32\hpbhks
rv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
d:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\snmp.e
xe
d:\PROGRA~1\NORTON~1\SPEED
D~1\nopdb.
exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.ex
e
C:\WINDOWS\system32\rundll
32.exe
C:\WINDOWS\system32\fxssvc
.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\yywqiw
.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
D:\Program Files\Norton Password Manager\AcctMgr.exe
D:\Program Files\Spyware Slayer\SpywareSlayer.Exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\Plaxo\2.0.3.16\Insta
llStub.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.e
xe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
D:\Documents and Settings\Norman Taylor\My Documents\Download\HiJackT
his\Hijack
This.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://start.earthlink.netR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://www.earthlink.net/partner/more/msie/button/search.htmlR0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = 127.0.0.1;;localhost;<loca
l>
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-
00C04FD644
97} - (no file)
R3 - URLSearchHook: (no name) - _{6E6DD93E-1FC3-4F43-8AFB-
1B7B90C9D3
EB} - (no file)
R3 - URLSearchHook: (no name) - {CA0E28FA-1AFD-4C21-A8DC-7
0EB5BE2F07
6} - C:\Program Files\SurfSideKick 2\SskBho.dll (file missing)
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: (no name) - {57E69D5A-6539-4d7d-9637-7
75DE8A385B
4} - (no file)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\WINDOWS\Downloaded Program Files\ycomp5_1_6_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\windows\googletoolbar4.
dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A
37C9A5676A
7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt
.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
859DF00B1D
6} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AcctMgr] D:\Program Files\Norton Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [Spyware Slayer] D:\Program Files\Spyware Slayer\SpywareSlayer.Exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.0.3.16\Insta
llStub.exe
-a
O6 - HKCU\Software\Policies\Mic
rosoft\Int
ernet Explorer\Control Panel present
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsear
ch.htm
O8 - Extra context menu item: &Google Search - res://c:\windows\GoogleToo
lbar4.dll/
cmsearch.h
tml
O8 - Extra context menu item: Backward Links - res://c:\windows\GoogleToo
lbar4.dll/
cmbacklink
s.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\windows\GoogleToo
lbar4.dll/
cmcache.ht
ml
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office10\
EXCEL.EXE/
3000
O8 - Extra context menu item: Similar Pages - res://c:\windows\GoogleToo
lbar4.dll/
cmsimilar.
html
O8 - Extra context menu item: Translate into English - res://c:\windows\GoogleToo
lbar4.dll/
cmtrans.ht
ml
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\T
p1150\scri
1150a.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict
.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch
.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\WINDOWS\System32\msjava
.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\WINDOWS\System32\msjava
.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-0
0C04FAE2D4
F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-0
0C04FAE2D4
F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-0
0C04FAE2D4
F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
0C0F0318AF
E} - C:\WINDOWS\System32\Shdocv
w.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B
7D41EF1CB5
2} - C:\Program Files\AWS\WeatherBug\Weath
er.exe (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O15 - Trusted Zone:
http://*.hp.comO16 - DPF: DigiChat Applet -
http://chat.universalclass.com/DigiChat/DigiClasses/Client_IE.cabO16 - DPF: Yahoo! Pool 2 -
http://download.games.yahoo.com/games/clients/y/potc_x.cabO16 - DPF: {00000EF1-0786-4633-87C6-1
AA7A44297D
A} -
http://bannerfarm.ace.advertising.com/bannerfarm/47041/WrapperOuter1153.EXEO16 - DPF: {0878B424-1F95-4E26-B5AB-F
0D349D8965
0} -
ftp://download2.us4.outblaze.com/download/mail.com/emailalert/mail_mcea115.cabO16 - DPF: {08BEF711-06DA-48B2-9534-8
02ECAA2E4F
9} (PlxInstall Class) -
https://www.plaxo.com/down/release/PlaxoInstall.cabO16 - DPF: {15C3C7A4-9676-11D3-9799-0
060087190B
9} -
http://www.movieplugin.com/plugin/plugin.exeO16 - DPF: {17492023-C23A-453E-A040-C
7C580BBF70
0} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409O16 - DPF: {1DF36010-E276-11D4-A7C0-0
0C04F0453D
D} (Stamps.com Secure Postal Account Registration) -
https://secure.stamps.com/download/us/registration/2_0_0_755/sdcregie.cabO16 - DPF: {205FF73B-CA67-11D5-99DD-4
4455354000
6} (CInstall Class) -
http://www.errorguard.com/installation/Install.cabO16 - DPF: {2B323CD9-50E3-11D3-9466-0
0A0C970049
8} -
http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cabO16 - DPF: {60EFC337-15C2-4369-B2A0-3
429B071D8B
8} (WebProgramManager Class) -
http://isupport4.hp.com/awebui/jsp/answerweb/applets/HPISWebManager.CABO16 - DPF: {7411047A-48E1-4EC9-8AC1-0
88087AD368
F} (QuickBooks GLDownload Control) -
https://eul1.intuit.com/NetPay/QBGL/GLDownload.cabO16 - DPF: {79849612-A98F-45B8-95E9-4
D13C7B6B35
C} (Loader2 Control) -
http://static.topconverting.com/activex/loader2.ocxO16 - DPF: {8EDAD21C-3584-4E66-A8AB-E
B0E5584767
D} -
http://toolbar.google.com/data/GoogleActivate.cabO16 - DPF: {94B82441-A413-4E43-8422-D
49930E6976
4} (TLIEFlashObj Class) -
https://rtc.webresponse.one.microsoft.com/media/xp/TLIEFlash.CABO16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-0
0608CEC297
B} -
http://start1.aaa1screensavers.com/10041.exeO16 - DPF: {A17E30C4-A9BA-11D4-8673-6
0DB54C1000
0} (YahooYMailTo Class) -
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dllO16 - DPF: {BE5431D2-0F30-11D4-89D9-0
0C04F509C0
A} (SDCInstaller Class) -
http://www.stamps.com/download/us/cab/stamps/stamps.cab?r=0.409881591796875&file=stamps.cabO16 - DPF: {C68AE9C0-0909-4DDC-B661-C
1AFB9F5AE5
1} -
http://207.44.240.65/ad/2_0.exeO16 - DPF: {CE185270-53A5-11D9-9669-0
800200C9A6
6} -
http://www.ouchvideo.com/mmviewer_ic2.cabO16 - DPF: {D9EC0A76-03BF-11D4-A509-0
090270F86E
3} -
http://bannerfarm.ace.advertising.com/bannerfarm/47041/WrapperOuter1155.EXEO16 - DPF: {E2F2B9D0-96B9-4B25-B90C-6
36ECB207D1
8} -
http://www.whenusearch.com/WUInstSECS.cabO16 - DPF: {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} (Yahoo! Companion) -
http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cabO18 - Filter: text/html - (no CLSID) - (no file)
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\driver
s\CDAC11BA
.EXE
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\Symantec\NORTO
N~1\GHOSTS
~2.EXE
O23 - Service: HP Status - Hewlett-Packard Company - C:\WINDOWS\System32\hpb2ks
rv.exe
O23 - Service: HP Status Print - Unknown - C:\WINDOWS\System32\hpbhks
rv.exe
O23 - Service: ISSvc - Symantec Corporation - D:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCE
S.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service - Symantec Corporation - D:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection - Symantec Corporation - d:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm
11.exe
O23 - Service: SAVScan - Symantec Corporation - D:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMAN
T~1\SCRIPT
~1\SBServ.
exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - d:\PROGRA~1\NORTON~1\SPEED
D~1\nopdb.
exe
O23 - Service: Sony SPTI Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.ex
e
O23 - Service: ZESOFT - Unknown - C:\WINDOWS\zeta.exe (file missing)