Hello,
I've spent many hours now searching for all types of worms. The symptom is that the explorer.exe is using 100% of my memory when I start up the computer. It loads my wallpaper and goes no further. I have run in safe mode and even created a second profile in windows xp that runs without problems.
I also ran the remover for W32/Gaobot worm from Symentec and it didnt find anything and also ran a couple of trojan detectors with no luck.
I did notice two dllhost -- one all caps DLLHOST.EXE in :/I386 and the other lower case dllhost.exe in the SYSTEM32 folder. Could one of these be the culprit?
Here's my hijack log...thanks in advance.
Logfile of HijackThis v1.97.7
Scan saved at 9:52:34 AM, on 1/22/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Administrator.WHO
OPASS-MQG2
N2.001\Loc
al Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.
exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://search.shopnav.com/apps/epa/epa?cid=shnv9886&s=R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
http://www.shopnav.com/search/9886/search.htmlR0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Toolbar,LinksFold
erName =
O1 - Hosts: 216.177.73.139 ieautosearch
O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-0
7CFE51CFF1
0} - C:\Program Files\MySearch\bar\1.bin\S
4BAR.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: (no name) - {136A9D1D-1F4B-43D4-8359-6
F238244925
5} - C:\Program Files\SuperBar\SuperBar.Dl
l
O2 - BHO: (no name) - {14b3d246-6274-40b5-8d50-6
c2ade2ab29
b} - C:\Program Files\Srng\SNHelper.dll
O2 - BHO: (no name) - {6B35C56C-76A5-40C8-AAE0-0
93471D7906
7} - C:\WINDOWS\System32\ir3g2_
32.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
1.dll
O3 - Toolbar: SuperBar - {F3C01D95-081D-4739-9C2B-A
0C2D111C43
7} - C:\Program Files\SuperBar\SuperBar.Dl
l
O3 - Toolbar: My &Search Bar - {014DA6C9-189F-421a-88CD-0
7CFE51CFF1
0} - C:\Program Files\MySearch\bar\1.bin\S
4BAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [iPodManager] C:\Program Files\iPod\bin\iPodManager
.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATC
H Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtr
ay.exe
O4 - HKLM\..\Run: [IBWin Monitor] "C:\Program Files\IBackup For Windows\IBMonitor.exe" Min
O4 - HKLM\..\Run: [IBWin Background process] "C:\Program Files\IBackup For Windows\IBackground.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\
drivers\w3
2x86\3\hpz
tsb06.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.
exe
O4 - HKLM\..\Run: [AltnetPointsManager] c:\program files\altnet\points manager\points manager.exe -s
O4 - HKLM\..\Run: [WINSTA~1.EXE] C:\WINDOWS\System\WINSTA~1
.EXE -b
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.
exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [FineReader7NewsReaderPro]
"C:\Program Files\ABBYY FineReader 7.0 Professional Edition\AbbyyNewsReader.ex
e"
O4 - HKLM\..\Run: [SBHC] C:\Program Files\SuperBar\sbhc.exe
O4 - HKLM\..\Run: [msbb] C:\Program Files\Blue Haven Media\Value Added Software\msbb.exe
O4 - HKLM\..\Run: [EbatesMoeMoneyMaker] wjview /cp:p "C:\Program Files\EbatesMoeMoneyMaker\
System\Cod
e" Main lp: "C:\Program Files\EbatesMoeMoneyMaker"
O4 - HKLM\..\Run: [Srng] \Program Files\Srng\Srng.exe
O4 - HKLM\..\Run: [ELRYFLS] C:\WINDOWS\ELRYFLS.exe
O4 - HKLM\..\Run: [BHORYEL] C:\WINDOWS\BHORYEL.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 3.8\THGuard.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dump
rep 0 -k
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EX
E
O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe
O4 - Global Startup: eFax.com Tray Menu.lnk = C:\Program Files\Common Files\efax\HotTray.exe
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Palm\HotSync.exe
O4 - Global Startup: hp instant support.lnk = C:\Program Files\Hewlett-Packard\hpis
\bin\matcl
i.exe
O4 - Global Startup: HP OfficeJet T Series Startup.lnk = C:\Program Files\Hewlett-Packard\HP OfficeJet T Series\Bin\HPOstr05.exe
O4 - Global Startup: Live Menu.lnk = C:\Program Files\Common Files\efax\Dllcmd32.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\Precis
ionTime.ex
e
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.d
ll
O16 - DPF: Yahoo! NFL GameChannel StatTracker -
http://aud16.sports.sc5.yahoo.com/java/y/nflgcst1008_x.cabO16 - DPF: {01A88BB1-1174-41EC-ACCB-9
63509EAE56
B} (SysProWmi Class) -
http://support.dell.com/systemprofiler/SysPro.CABO16 - DPF: {0D3983A9-4E29-4F33-8313-D
A22B29D3F8
7} (QuickBooks Online Edition Utilities Class v6) -
https://accounting.quickbooks.com/v10.118/qboax6.cabO16 - DPF: {0E8D0700-75DF-11D3-8B4A-0
008C7450C4
A} (DjVuCtl Class) -
http://www.lizardtech.com/plugins/en_US/DjVuControl_en_US.cabO16 - DPF: {30528230-99F7-4BB4-88D8-F
A1D4F56A2A
B} (YInstStarter Class) -
http://download.yahoo.com/dl/installs/yinst0309.cabO16 - DPF: {56336BCB-3D8A-11D6-A00B-0
050DA18DE7
1} (RdxIE Class) -
http://207.188.7.150/190282c5daab33f14e03/netzip/RdxIE601.cabO16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-0
0608CEC297
B} -
http://web.net2phone.com/products/commcenter/download/bin/IXCommCenter.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {E855A2D4-987E-4F3B-A51C-6
4D10A7E247
9} (EPSImageControl Class) -
http://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cab