?
Solved

HijackThis Log

Posted on 2006-04-20
9
Medium Priority
?
567 Views
Last Modified: 2010-04-12
I've cleaned a lot of spyware, adware, and viruses from a PC running Win 98.  It still freezes temporarily or runs slow sometimes.

Here's the HJT log.  Can someone look through it and tell me what looks like a potential problem in it?

Logfile of HijackThis v1.99.1
Scan saved at 12:32:40 PM, on 04/20/2006
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGAMSVR.EXE
C:\PROGRAM FILES\MICROSOFT BROADBAND NETWORKING\MSBNTRAY.EXE
C:\PROGRAM FILES\OLYMPUS\CAMEDIA MASTER 4.2\CM_CAMERA.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\MICROSOFT BROADBAND NETWORKING\IPHLPSVR.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGW.EXE
C:\HJT\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.att.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {16053E0E-8AE3-FE17-C1AF-F98ADEA7FA9C} - C:\WINDOWS\SYSTEM\KTR.DLL (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Cox Popup Blocker - {64634180-B0EA-48B6-82B7-9620D33362C1} - C:\PROGRAM FILES\COX\APPLICATIONS\APP\AUTHBHO.DLL (file missing)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\PROGRAM FILES\AOL\AOL TOOLBAR 2.0\AOLTB.DLL
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [Windows Plug and Play Service 32 BIT] WINMANAGER32.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVG7\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVG7\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVG7\AVGAMSVR.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [Windows Plug and Play Service 32 BIT] WINMANAGER32.EXE
O4 - HKLM\..\RunServices: [CurtainsSysSvc] c:\program files\cox\applications\app\AuthSL.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Startup: Microsoft Broadband Networking.lnk = C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
O4 - Startup: CAMEDIA Master.lnk = C:\Program Files\OLYMPUS\CAMEDIA Master 4.2\CM_camera.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://c:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\PROGRAM FILES\AOL\AOL TOOLBAR 2.0\AOLTB.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: MSN - {E19D474D-B5FD-11D2-AE0E-00C04FAEA83F} - C:\PROGRA~1\ONLINE~1\MSN50\OCX\MSNFORIE.DLL (file missing) (HKCU)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.att.net
O15 - Trusted Zone: *.elitemediagroup.net
O16 - DPF: {8EF27A70-DD04-11D6-B7F6-00A0C9CD5F8A} - http://www.quikshield.com/qshsetup.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O16 - DPF: {FFFF0001-0001-101A-A3C9-08002B2F49FB} - http://download.energy-factor.com/plug/dscert_652.exe
0
Comment
Question by:wskesler
  • 3
  • 2
  • 2
  • +2
9 Comments
 
LVL 37

Expert Comment

by:Harisha M G
ID: 16501842
Hi, here is the result of your logfile:

http://hijackthis.de/logfiles/cac5f1e789d405034a83fd82231373dc.html

Remove the "Nasty" entries and also the "Possibly Nasty" entries that you don't recognize


---
Harish
0
 
LVL 37

Accepted Solution

by:
Harisha M G earned 160 total points
ID: 16501891
wskesler, your log file contains many "Unknown" entries. Have you purposefully installed those softwares/components ?

Have you run spyware/virus scans? If not, try these:

http://en.ewido.net/en/
http://www.avast.com/eng/download-avast-home.html

0
 

Author Comment

by:wskesler
ID: 16503966
I've scanned the PC multiple times with updated Spybot and Ad-Aware SE.  Also installed, updated, and ran AVG antivirus.  All found lots of stuff that I deleted.  Not sure about some of the entries found in the HJT log, as this is a friend's teenager's PC (explains all the garbage).

Ewido doesn't support Win 98, but I did use just now load and run Avast...it found about 15 more things that it removed.  I'm worried about what it couldn't repair, though...

File Name: C:\\Windows\System.Dat
Malware Name: Win32:Volage-G (wrm)

Also, AVG scans find and can seem to remove a problem with C:\Windows\System\iniwin32.dll
0
Automating Your MSP Business

The road to profitability.
Delivering superior services is key to ensuring customer satisfaction and the consequent long-term relationships that enable MSPs to lock in predictable, recurring revenue. What's the best way to deliver superior service? One word: automation.

 
LVL 47

Assisted Solution

by:rpggamergirl
rpggamergirl earned 280 total points
ID: 16504180
Did you set IE default search to About:Blank? if not then fix those R's entries as well:

Fix these:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank  
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =  
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank  
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank  
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =  
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank  
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank  
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank  
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank  
R3 - URLSearchHook: (no name) - {16053E0E-8AE3-FE17-C1AF-F98ADEA7FA9C} - C:\WINDOWS\SYSTEM\KTR.DLL (file missing)
O4 - HKLM\..\Run: [Windows Plug and Play Service 32 BIT] WINMANAGER32.EXE
O4 - HKLM\..\RunServices: [Windows Plug and Play Service 32 BIT] WINMANAGER32.EXE
O15 - Trusted Zone: *.elitemediagroup.net

Ewido doesn't work for Windows 98, so you might like to try other scanners like;
these free online scanners:
http://www.pandasoftware.com/activescan/com/activescan_principal.htm
http://housecall.trendmicro.com/
0
 
LVL 29

Assisted Solution

by:blue_zee
blue_zee earned 160 total points
ID: 16508006

A good alternative to Ewido (for Win9x systems) is A-squared free

http://www.emsisoft.com/en/software/free/

Download, install, UPDATE and do a full system scan.

Zee
0
 
LVL 32

Expert Comment

by:r-k
ID: 16508093
For the files that could not be fixed by AV programs, boot into DOS mode, then rename the offending files, then boot in normal windows mode and re-run the scan. That should fix those.
0
 

Author Comment

by:wskesler
ID: 16517452
Thx for all the help so far.  Did most of what was recommended, and all of the scans that I run now come up clean.  When I start the PC, I can open and close Excel, Word, etc. multiple times with no problem.  Once I open Internet Explorer (which works fine), close it, and try again to open another application the PC just freezes, though.
0
 
LVL 32

Assisted Solution

by:r-k
r-k earned 200 total points
ID: 16517560
You could try repairing Internet Explorer:

To use the Internet Explorer Repair tool on Microsoft Windows 2000 and earlier versions of Windows

1.Click Start, point to Settings, and then click Control Panel.
 
2.Double-click the Add/Remove Programs icon.
 
3.Click Microsoft Internet Explorer 6 and Internet Tools.
 
4.Click Change/Remove (Microsoft® Windows® 2000).

-Or-

Click Add/Remove (Microsoft® Windows® 95, Microsoft® Windows® 98, and Microsoft® Windows NT® 4.0).
 
5.Click Repair Internet Explorer.

I got the above from: http://www.microsoft.com/technet/prodtechnol/ie/reskit/6/part7/z02ie6rk.mspx?mfr=true

You can check there for more details. If the repair fails then re-install Internet Explorer
 
0
 

Author Comment

by:wskesler
ID: 16530653
Thanks for all the help.  I split up points based on recommendations that progressively solved the problems.  Thanks again.
0

Featured Post

Upgrade your Question Security!

Add Premium security features to your question to ensure its privacy or anonymity. Learn more about your ability to control Question Security today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I've been an avid user and supporter of Malwarebytes Premium Version 2.x for years. It's an excellent product that runs alongside just about any Anti-Virus application without issues. It seems to have an uncanny ability to pick up many things that A…
Did you know that more than 4 billion data records have been recorded as lost or stolen since 2013? It was a staggering number brought to our attention during last week’s ManageEngine webinar, where attendees received a comprehensive look at the ma…
This Micro Tutorial will teach you how to add a cinematic look to any film or video out there. There are very few simple steps that you will follow to do so. This will be demonstrated using Adobe Premiere Pro CS6.
Loops Section Overview
Suggested Courses

755 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question