Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

PC problem :( HiJackThis Log Included


  • Please log in to reply
5 replies to this topic

#1 arcas

arcas

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:01:29 PM

Posted 17 February 2005 - 05:31 AM

There is some very strange things with this PC could you please help me out :thumbsup:. It works very slowly and there is some pop up pages wich POPS UP every 5-10 minutes. I know what should I delete but this Pc is very important and I don't want to crash it.

Logfile of HijackThis v1.99.0
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
E:\WINNT\System32\smss.exe
E:\WINNT\system32\csrss.exe
E:\WINNT\system32\winlogon.exe
E:\WINNT\system32\services.exe
E:\WINNT\system32\lsass.exe
E:\WINNT\system32\svchost.exe
E:\WINNT\system32\spoolsv.exe
E:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
E:\WINNT\System32\svchost.exe
E:\WINNT\system32\hidserv.exe
E:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
E:\WINNT\system32\regsvc.exe
E:\WINNT\system32\MSTask.exe
E:\WINNT\System32\WBEM\WinMgmt.exe
E:\WINNT\system32\faxsvc.exe
E:\WINNT\Explorer.EXE
E:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
E:\WINNT\system32\internat.exe
E:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
E:\WINNT\system32\smbdins.exe
E:\WINNT\system32\sethcd.exe
E:\Program Files\Microsoft Office\Office\WINWORD.EXE
E:\Program Files\Cyrilla\Nav2000.exe
E:\Program Files\Microsoft Office\Office\EXCEL.EXE
K:\Nikolai\AntiSpamFull\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = http://clearsurfing.net/srch.php?qq=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - {B96871E7-D500-3EF9-239E-BEF3C4EB87D2} - CToolBar.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1F7D5835-0A51-4191-A85D-14589CA8C501} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5EEEDCEA-C4F8-4B22-B79B-1792B10262B6} - (no file)
O2 - BHO: (no name) - {EE6724FF-9928-415F-9A7B-C9041388D4EB} - (no file)
O3 - Toolbar: FreshBar - {06ABAA2D-34AB-4902-A326-409BD9B9A7A5} - E:\WINNT\system32\iesp2.dll
O4 - HKLM\..\Run: [Alternative Cyrillic] E:\WINNT\cyrstart.exe
O4 - HKLM\..\Run: [vptray] E:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AliceSD] forces_elite.exe
O4 - HKLM\..\Run: [XTermInit] ERTYDF.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [WareOut] "E:\Program Files\WareOut\WareOut.exe"
O4 - HKCU\..\Run: [XTermInit] Serviceprocess.exe
O4 - HKCU\..\Run: [SysEntry] Shaitan1678.exe
O4 - HKCU\..\Run: [prcmon] cnftips.exe
O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Start spyware remover - {BF69DF00-2734-477F-8257-27CD04F88779} - E:\Program Files\WareOut\WareOut.exe (HKCU)
O9 - Extra 'Tools' menuitem: Start spyware remover - {BF69DF00-2734-477F-8257-27CD04F88779} - E:\Program Files\WareOut\WareOut.exe (HKCU)
O16 - DPF: {26D73573-F1B3-48C9-A989-E6CE071957A1} - http://akamai.downloadv3.com/binaries/EGDA...ACCESS_1057.cab
O16 - DPF: {5B132B38-9E37-4D05-B8D6-A274C32D5234} (ActiveX_DownloadAndRun_0 Control) - http://www.worlds-best-online-casinos.com/down1.cab
O16 - DPF: {F72BC3F0-6C20-4793-9DDA-258589D8A907} - http://akamai.downloadv3.com/binaries/IA/netslv32_EN.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0DE378D-623F-46E8-85B7-1F2AB652129D}: NameServer = 69.50.188.180,195.225.176.31
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 69.50.188.180,195.225.176.31
O23 - Service: DefWatch - Symantec Corporation - E:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - E:\WINNT\System32\dmadmin.exe
O23 - Service: Symantec AntiVirus Client - Symantec Corporation - E:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - E:\WINNT\system32\HPZipm12.exe

Edited by arcas, 17 February 2005 - 06:22 AM.


BC AdBot (Login to Remove)

 


#2 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,639 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:02:29 PM

Posted 17 February 2005 - 05:21 PM

O4 - HKLM\..\Run: [Alternative Cyrillic] E:\WINNT\cyrstart.exe
O4 - HKLM\..\Run: [AliceSD] forces_elite.exe
O4 - HKLM\..\Run: [XTermInit] ERTYDF.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [WareOut] "E:\Program Files\WareOut\WareOut.exe"
O4 - HKCU\..\Run: [XTermInit] Serviceprocess.exe
O4 - HKCU\..\Run: [SysEntry] Shaitan1678.exe
O4 - HKCU\..\Run: [prcmon] cnftips.exe


Print out these instructions and then close all windows including Internet Explorer.

Then I want you to fix some of those entries. Please do the following:

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

How to see hidden files in Windows

Run Hijackthis again, click scan, and Put a checkmark next to each of these. Then click the Fix button:

R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = http://clearsurfing.net/srch.php?qq=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - {B96871E7-D500-3EF9-239E-BEF3C4EB87D2} - CToolBar.dll (file missing)
O2 - BHO: (no name) - {1F7D5835-0A51-4191-A85D-14589CA8C501} - (no file)
O2 - BHO: (no name) - {5EEEDCEA-C4F8-4B22-B79B-1792B10262B6} - (no file)
O2 - BHO: (no name) - {EE6724FF-9928-415F-9A7B-C9041388D4EB} - (no file)
O3 - Toolbar: FreshBar - {06ABAA2D-34AB-4902-A326-409BD9B9A7A5} - E:\WINNT\system32\iesp2.dll
O4 - HKLM\..\Run: [Alternative Cyrillic] E:\WINNT\cyrstart.exe
O4 - HKLM\..\Run: [AliceSD] forces_elite.exe
O4 - HKLM\..\Run: [XTermInit] ERTYDF.exe
O4 - HKCU\..\Run: [WareOut] "E:\Program Files\WareOut\WareOut.exe"
O4 - HKCU\..\Run: [XTermInit] Serviceprocess.exe
O4 - HKCU\..\Run: [SysEntry] Shaitan1678.exe
O4 - HKCU\..\Run: [prcmon] cnftips.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Start spyware remover - {BF69DF00-2734-477F-8257-27CD04F88779} - E:\Program Files\WareOut\WareOut.exe (HKCU)
O9 - Extra 'Tools' menuitem: Start spyware remover - {BF69DF00-2734-477F-8257-27CD04F88779} - E:\Program Files\WareOut\WareOut.exe (HKCU)
O16 - DPF: {26D73573-F1B3-48C9-A989-E6CE071957A1} - http://akamai.downloadv3.com/binaries/EGDA...ACCESS_1057.cab
O16 - DPF: {5B132B38-9E37-4D05-B8D6-A274C32D5234} (ActiveX_DownloadAndRun_0 Control) - http://www.worlds-best-online-casinos.com/down1.cab
O16 - DPF: {F72BC3F0-6C20-4793-9DDA-258589D8A907} - http://akamai.downloadv3.com/binaries/IA/netslv32_EN.cab

Reboot your computer into Safe Mode

Then delete these files or directories (Do not be concerned if they do not exist)

E:\WINNT\system32\iesp2.dll
E:\WINNT\cyrstart.exe
c:\windows\system32\forces_elite.exe
c:\windows\system32\ERTYDF.exe
c:\windows\system32\Serviceprocess.exe
c:\windows\system32\Shaitan1678.exe
c:\windows\system32\cnftips.exe
E:\Program Files\WareOut\

Reboot your computer to go back to normal mode and post a new log.

#3 arcas

arcas
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:01:29 PM

Posted 23 February 2005 - 05:28 AM

Thanks for everything and Here is the new log

Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
E:\WINNT\System32\smss.exe
E:\WINNT\system32\csrss.exe
E:\WINNT\system32\winlogon.exe
E:\WINNT\system32\services.exe
E:\WINNT\system32\lsass.exe
E:\WINNT\system32\svchost.exe
E:\WINNT\system32\spoolsv.exe
E:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
E:\WINNT\System32\svchost.exe
E:\WINNT\system32\hidserv.exe
E:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
E:\WINNT\system32\regsvc.exe
E:\WINNT\system32\MSTask.exe
E:\WINNT\System32\WBEM\WinMgmt.exe
E:\WINNT\system32\faxsvc.exe
E:\WINNT\Explorer.EXE
E:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
E:\WINNT\system32\internat.exe
K:\Nikolai\AntiSpamFull\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Name - {6B0FE8B9-EE9A-4755-84B8-71F15BD70340} - E:\WINNT\system32\msqbf.dll
O4 - HKLM\..\Run: [Alternative Cyrillic] E:\WINNT\cyrstart.exe
O4 - HKLM\..\Run: [vptray] E:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Security iGuard] E:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [WareOut] "E:\Program Files\WareOut\WareOut.exe"
O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe
O13 - WWW. Prefix: http://
O16 - DPF: {BE964208-66F0-48FB-8F53-0C2BC35A610A} (UMediaPlayer Class) - http://www.umediaserver.net/bin/UMediaControl3.cab
O23 - Service: DefWatch - Symantec Corporation - E:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - E:\WINNT\System32\dmadmin.exe
O23 - Service: Symantec AntiVirus Client - Symantec Corporation - E:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - E:\WINNT\system32\HPZipm12.exe

#4 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,639 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:02:29 PM

Posted 23 February 2005 - 01:02 PM

Go into your add/remove programs and uninstall ware out. Then post a new log

#5 arcas

arcas
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:01:29 PM

Posted 25 February 2005 - 02:59 AM

There is still problems with poping out windows :thumbsup:
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
E:\WINNT\System32\smss.exe
E:\WINNT\system32\csrss.exe
E:\WINNT\system32\winlogon.exe
E:\WINNT\system32\services.exe
E:\WINNT\system32\lsass.exe
E:\WINNT\system32\svchost.exe
E:\WINNT\system32\spoolsv.exe
E:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
E:\WINNT\System32\svchost.exe
E:\WINNT\system32\hidserv.exe
E:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
E:\WINNT\system32\regsvc.exe
E:\WINNT\system32\MSTask.exe
E:\WINNT\System32\WBEM\WinMgmt.exe
E:\WINNT\system32\faxsvc.exe
E:\WINNT\Explorer.EXE
E:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
E:\winnt\system32\iclrhef.exe
E:\WINNT\system32\internat.exe
E:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
E:\Program Files\SA Dictionary 2004 Datacenter\Diction.exe
E:\WINNT\system32\smbdins.exe
E:\WINNT\system32\sethcd.exe
K:\Nikolai\AntiSpamFull\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [Alternative Cyrillic] E:\WINNT\cyrstart.exe
O4 - HKLM\..\Run: [vptray] E:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [iclrhef] e:\winnt\system32\iclrhef.exe -start
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0DE378D-623F-46E8-85B7-1F2AB652129D}: NameServer = 69.50.188.180,195.225.176.31
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 69.50.188.180,195.225.176.31
O23 - Service: DefWatch - Symantec Corporation - E:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - E:\WINNT\System32\dmadmin.exe
O23 - Service: Symantec AntiVirus Client - Symantec Corporation - E:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - E:\WINNT\system32\HPZipm12.exe

#6 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,639 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:02:29 PM

Posted 25 February 2005 - 11:34 AM

Fix this:

O4 - HKLM\..\Run: [iclrhef] e:\winnt\system32\iclrhef.exe -start

Reboot and delete :

e:\winnt\system32\iclrhef.exe

Then do the following:
Enter your control panel and double click on Network Connections. Then right click on your default connection, usually local area connection for cable and dsl, and left click on properties. Double-click on the Internet Protocol (TCP/IP) item and select the radio dial that says Obtain DNS servers automatically

Press OK twice to get out of the properties screen and reboot if it asks.

Then post a new log




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users