Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I dont Know what to delete from this Log


  • Please log in to reply
1 reply to this topic

#1 Aparny

Aparny

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:02:55 AM

Posted 21 May 2005 - 09:01 PM

StartupList report, 22/05/2005, 11:54:25 AM
StartupList version: 1.52.2
Started from : C:\WINDOWS\TEMP\HIJACKTHIS.EXE
Detected: Windows ME (Win9x 4.90.3000)
Detected: Internet Explorer v6.00 (6.00.2600.0000)
* Using default options
==================================================

Running processes:

C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\SYSTEM\LVCOMS.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\DELFIN\PROMULGATE\PGMONITR.EXE
C:\PROGRAM FILES\MOUSE\AMOUMAIN.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\IEMSVOPQ.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\ZONE LABS\INTEGRITY CLIENT\ICLIENT.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\WINWORD.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE
C:\WINDOWS\TEMP\HIJACKTHIS.EXE

--------------------------------------------------

Listing of startup folders:

Shell folders Common Startup:
[C:\WINDOWS\All Users\Start Menu\Programs\StartUp]
Integrity Client.lnk = C:\Program Files\Zone Labs\Integrity Client\iclient.exe

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
TaskMonitor = C:\WINDOWS\taskmon.exe
PCHealth = C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
SystemTray = SysTray.Exe
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
internat.exe = internat.exe
LVComs = C:\WINDOWS\SYSTEM\LVComS.exe
Norton Auto-Protect = C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
LoadQM = loadqm.exe
MSN Messenger = C:\MY DOCUMENTS\MESSENGER SERVICE RECEIVED FILES\PIC1324(1)(1)(1)(1)(2)(1).exe
Mahesh = C:\WINDOWS\SYSTEM\Mahesh.exe
School = C:\WINDOWS\SYSTEM\School.exe
MediaLoads Installer = "C:\Program Files\DownloadWare\dw.exe" /H
CMESys = "C:\PROGRAM FILES\COMMON FILES\CMEII\CMESYS.EXE"
PromulGate = "C:\Program Files\DelFin\PromulGate\PgMonitr.exe"
WhenUSave = C:\PROGRA~1\SAVE\Save.exe
WT GameChannel = C:\Program Files\WildTangent\Apps\GameChannel.exe
AltnetPointsManager = c:\program files\altnet\points manager\points manager.exe -s
updmgr = C:\Program Files\Common files\updmgr\updmgr.exe
ohzqlte = "C:\WINDOWS\SYSTEM\OHZQLTE.exe"
mswspl =
stcinstaller = c:\installer\id53.exe
ClrSchLoader = \Progra~1\Lycos\IEagent\Loader.exe
Bargains = C:\Program Files\Bargain Buddy\bin2\bargains.exe
ALCHEM = C:\WINDOWS\ALCHEM.exe
WildTangent CDA = RUNDLL32.exe C:\PROGRA~1\WILDTA~1\APPS\CDA\CDAENG~1.DLL,cdaEngineMain
WheelMouse = Amoumain.exe
TkBellExe = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
yjicoiwqwxr = C:\WINDOWS\SYSTEM\iemsvopq.exe
WebRebates0 = "C:\PROGRAM FILES\WEB_REBATES\WebRebates0.exe"
Spam list less loud = C:\WINDOWS\All Users\Application Data\Closeobjspamlist\Heckshim.exe
RFX_auto_upgrade =
New.net Startup = rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
QuickTime Task = "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
satmat = C:\WINDOWS\SATMAT.exe
SADP32M = C:\WINDOWS\SYSTEM\SADP32M.exe

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

InstMsi0 = C:\WINDOWS\SYSTEM\msiexec.exe /regserver
InstMsi1 = rundll32.exe C:\WINDOWS\SYSTEM\advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\Installer\InstMsi0"

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
SchedulingAgent = mstask.exe
*StateMgr = C:\WINDOWS\System\Restore\StateMgr.exe
StillImageMonitor = C:\WINDOWS\SYSTEM\STIMON.EXE
MessengerPlus3 = "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
TrueVector = C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

winpopup = C:\WINDOWS\winupie.exe
sp = C:\sp.exe
Idoldrive = C:\WINDOWS\APPLIC~1\GRIMDO~1\spamfree.exe

--------------------------------------------------

File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(Default) = C:\WINDOWS\NOTEPAD.EXE %1

--------------------------------------------------

C:\WINDOWS\WININIT.INI listing:
(Created 22/5/2005, 10:49:32)

[Rename]
C:\WINDOWS\SYSTEM\MSI.DLL=C:\WINDOWS\SYSTEM\TBM11F5.TMP

--------------------------------------------------

C:\WINDOWS\WININIT.BAK listing:
(Created 20/5/2005, 18:47:34)

[Rename]

--------------------------------------------------

C:\AUTOEXEC.BAT listing:

SET BLASTER=A220 I7 D1 H7 P330 T6
SET SBPCI=C:\SBPCI
SET windir=C:\WINDOWS
SET winbootdir=C:\WINDOWS
SET COMSPEC=C:\WINDOWS\COMMAND.COM
SET PATH=C:\WINDOWS;C:\WINDOWS\COMMAND
SET PROMPT=$p$g
SET TEMP=C:\WINDOWS\TEMP
SET TMP=C:\WINDOWS\TEMP

--------------------------------------------------

C:\WINDOWS\WINSTART.BAT listing:

C:\WINDOWS\tmpcpyis.bat

--------------------------------------------------


Enumerating Browser Helper Objects:

(no name) - C:\WINDOWS\IEHELPER.DLL - {CE7C3CF0-4B15-11D1-ABED-709549C10000}
(no name) - C:\PROGRAM FILES\WIPE SOAP\2 TEST.DLL (file missing) - {AA328B58-7D65-C14E-2186-B349A3F7C52A}
(no name) - C:\WINDOWS\2_0_1browserhelper2.dll - {83DE62E0-5805-11D8-9B25-00E04C60FAF2}
(no name) - C:\PROGRAM FILES\BARGAIN BUDDY\BIN2\APUC.DLL (file missing) - {CE31A1F7-3D90-4874-8FBE-A5D97F8BC8F1}
(no name) - C:\PROGRA~1\PERFEC~1\BHO\PERFEC~1.DLL (file missing) - {00D6A7E7-4A97-456f-848A-3B75BF7554D7}
MediaLoads Enhanced - C:\PROGRAM FILES\MEDIALOADS ENHANCED\ME2.DLL - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E}
NavErrRedir Class - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL (file missing) - {5D60FF48-95BE-4956-B4C6-6BB168A70310}
(no name) - C:\WINDOWS\ALL USERS\APPLICATION DATA\SETUP\SETUP.DLL - {2E65A557-173C-4DE9-860B-28FC5CACA542}
(no name) - C:\WINDOWS\APPLICATION DATA\WIPE SOAP\POLL TRUST.EXE (file missing) - {6BDC4ABD-BD13-0119-B2BE-BD7C7A7B20F4}
(no name) - C:\Program Files\NewDotNet\newdotnet6_38.dll - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E}
(no name) - C:\WINDOWS\TWAINTEC.DLL - {000020DD-C72E-4113-AF77-DD56626C6C42}
(no name) - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}

--------------------------------------------------

Enumerating Task Scheduler jobs:

Tune-up Application Start.job
PCHealth Scheduler for Data Collection.job
Scan for Viruses.job
Symantec NetDetect.job
6FAB1D2A6A695253.job
9BCAF94068E2020B.job
9A505883919D8FBA.job
AC2247616E7C8684.job

--------------------------------------------------

Enumerating Download Program Files:

[{10000000-1000-0000-1000-000000000000}]
CODEBASE = ms-its:mhtml:file://C:\foo.mht!http://www.free32.com/POP.CHM::/sp.exe

[MessengerStatsClient Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\MESSENGERSTATSCLIENT.DLL
CODEBASE = http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
CODEBASE = http://download.macromedia.com/pub/shockwa...ash/swflash.cab

[MSN Photo Upload Tool]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\MSNPUPLD.DLL
CODEBASE = http://spaces.msn.com//PhotoUpload/MsnPUpld.cab

--------------------------------------------------

Enumerating Winsock LSP files:

NameSpace #2: C:\Program Files\NewDotNet\newdotnet6_38.dll
Protocol #1: C:\Program Files\NewDotNet\newdotnet6_38.dll
Protocol #2: C:\Program Files\NewDotNet\newdotnet6_38.dll
Protocol #9: C:\Program Files\NewDotNet\newdotnet6_38.dll
Protocol #10: C:\Program Files\NewDotNet\newdotnet6_38.dll

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

WebCheck: C:\WINDOWS\SYSTEM\WEBCHECK.DLL
AUHook: C:\WINDOWS\SYSTEM\AUHOOK.DLL

--------------------------------------------------
End of report, 9,328 bytes
Report generated in 0.132 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only

BC AdBot (Login to Remove)

 


#2 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:03:55 AM

Posted 21 May 2005 - 10:30 PM

Hello Aparny and welcome to the BC forums. We need a complete HijackThis (HJT) log file to be able to analyze what is happening on your computer. If you do not have a copy of HijackThis or do not have the latest version (1.99.1) then download it from here: HijackThis_sfx.exe
Double-click on the file you just downloaded and click on the UnZip button to install the program. It will be installed to the C:\Program Files\HijackThis\ folder by default.

Start HijackThis and click the Do a system scan and save a log button to perform a scan and create a log file. When the scan is complete, Notepad will open up with the log file in it. While in Notepad, press Ctrl-A to select all text and then Ctrl-C to copy the text to the clipboard.

POST the log in this thread using the Add Reply button. Click in the data-entry window and press Ctrl-V to paste the log into the window. Add any other comments which you believe might be helpful in our analysis. and click the Add Reply button.

I will review your log when it comes in.


DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL I CHECK THE LOG, AS SOME OF THE FILES ARE LEGIT AND VITAL TO THE FUNCTION OF YOUR COMPUTER

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users