Start a Conversation

Unsolved

This post is more than 5 years old

B

243

May 20th, 2005 19:00

HiJackthis log

​ Logfile of HijackThis v1.99.1 ​
​Scan saved at 3:38:41 PM, on 5/20/2005 ​
​Platform: Windows XP (WinNT 5.01.2600) ​
​MSIE: Internet Explorer v6.00 (6.00.2600.0000) ​
​ Running processes: ​
​C:\WINDOWS\System32\smss.exe ​
​C:\WINDOWS\system32\services.exe ​
​C:\WINDOWS\system32\lsass.exe ​
​C:\WINDOWS\system32\svchost.exe ​
​C:\WINDOWS\System32\svchost.exe ​
​C:\WINDOWS\system32\spoolsv.exe ​
​C:\WINDOWS\Explorer.EXE ​
​C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe ​
​C:\Program Files\Norton AntiVirus\navapsvc.exe ​
​C:\WINDOWS\wanmpsvc.exe ​
​C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe ​
​C:\WINDOWS\System32\hkcmd.exe ​
​C:\Program Files\Real\RealPlayer\RealPlay.exe ​
​C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe ​
​C:\PROGRA~1\NORTON~1\navapw32.exe ​
​C:\Program Files\QuickTime\qttask.exe ​
​C:\Program Files\Common files\updmgr\updmgr.exe ​
​C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe ​
​C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe ​
​C:\WINDOWS\System32\wuauclt.exe ​
​C:\WINDOWS\System32\svchost.exe ​
​c:\program files\internet explorer\iexplore.exe ​
​C:\WINDOWS\System32\rasautou.exe ​
​C:\PROGRA~1\AT&T\WnClient\Programs\WNConnect.exe ​
​C:\PROGRA~1\AT&T\WnClient\Programs\WNCSMS~1.EXE ​
​C:\Program Files\Internet Explorer\iexplore.exe ​
​C:\Program Files\Microsoft Money\System\urlmap.exe ​
​C:\HJT\HijackThis.exe ​
​ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = ​​http://www.dellnet.com​​ ​
​R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = ​​http://rd.companion.yahoo.com/slv/ycheck/as/*http://www.yahoo.com/search/ie.html​​ ​
​R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = ​​http://rd.companion.yahoo.com/slv/ycheck/as/*http://www.yahoo.com​​ ​
​R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = ​​http://www.att.net/​​ ​
​R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = ​​http://www.att.net​​ ​
​R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = ​​http://www.dellnet.com​​ ​
​R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = ​​http://rd.companion.yahoo.com/slv/ycheck/as/*http://search.yahoo.com/search?p=%s​​ ​
​R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by AT&T WorldNet Service ​
​R3 - URLSearchHook: PerfectNavBHO Class - {0428FFC7-1931-45b7-95CB-3CBB919777E1} - C:\PROGRA~1\PERFEC~1\BHO\PERFEC~1.DLL ​
​O2 - BHO: Yahoo! Companion BHO - {02478D28-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5_0_2_6.dll ​
​O2 - BHO: NavErrRedir Class - {0428FFC7-1931-45b7-95CB-3CBB919777E1} - C:\PROGRA~1\PERFEC~1\BHO\PERFEC~1.DLL ​
​O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL ​
​O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll ​
​O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll ​
​O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll ​
​O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5_0_2_6.dll ​
​O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll ​
​O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL ​
​O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx ​
​O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe ​
​O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe ​
​O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe ​
​O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER ​
​O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" ​
​O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe ​
​O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime ​
​O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe ​
​O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" ​
​O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet ​
​O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background ​
​O4 - HKCU\..\Run: [ModemOnHold] C:\PROGRA~1\DELLMO~1\moh.exe ​
​O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe ​
​O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe ​
​O4 - Global Startup: Digital Line Detect.lnk = ? ​
​O4 - Global Startup: Image Transfer.lnk = ? ​
​O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ? ​
​O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll ​
​O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0819.dll ​
​O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm ​
​O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm ​
​O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll ​
​O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll ​
​O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE ​
​O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE ​
​O14 - IERESET.INF: START_PAGE_URL=http://www.att.net ​
​O16 - DPF: Yahoo! Literati - ​​http://download.games.yahoo.com/games/clients/y/tt0_x.cab​​ ​
​O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - ​​http://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cab​​ ​
​O17 - HKLM\System\CCS\Services\Tcpip\..\{E0F0E9B8-AB67-45E3-AB3C-A7045901DCA7}: NameServer = 204.127.160.3 12.102.240.1 ​
​O20 - Winlogon Notify: drct16 - C:\WINDOWS\SYSTEM32\drct16.dll ​
​O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll ​
​O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe ​
​O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe ​
​O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe ​
​O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe ​
​ ​

3 Apprentice

 • 

8.8K Posts

May 21st, 2005 18:00

Hi and welcome.



When we're done cleaning off your system, i'd recommend that you install all the critical windows updates available from Microsoft, upto service pack 1. This will help to make your system more secure and prevent many ' problems' from reoccuring in the future.




Go to Add/Remove programs and remove(uninstall) the following, if present:

Web Related

The above could appear anywhere within the entry. Be careful not to remove any personal or system software.



Run HiJackThis then:

1. Click " Config..."
2. Click " Misc Tools"
3. Click " Open Process manager"

-

Next, while holding down the CTRL key, locate ( if present) and click on ( highlight) each of the following:

C:\Program Files\Common files\updmgr\updmgr.exe

Now double-check and make sure that only those item(s) above are highlighted, then click " Kill process". Now, click " Refresh", check again, and repeat this step if any remain.



Now, let's open a command prompt and unregister the dll(s) we're going to remove, by entering the following:

regsvr32 /u PERFEC~1.DLL
regsvr32 /u MYBAR.DLL

It's ok, if these aren't found or 'error' out. If you want, just copy and paste the individual lines to the command prompt to save on the typing.



Run HiJackThis and click " Scan", then check(tick) the following, if present:


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.companion.yahoo.com/slv/ycheck/as/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://rd.companion.yahoo.com/slv/ycheck/as/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.companion.yahoo.com/slv/ycheck/as/*http://search.yahoo.com/search?p=%s

R3 - URLSearchHook: PerfectNavBHO Class - {0428FFC7-1931-45b7-95CB-3CBB919777E1} - C:\PROGRA~1\PERFEC~1\BHO\PERFEC~1.DLL

O2 - BHO: NavErrRedir Class - {0428FFC7-1931-45b7-95CB-3CBB919777E1} - C:\PROGRA~1\PERFEC~1\BHO\PERFEC~1.DLL
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL

O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm


Now, with all windows closed except HiJackThis, click " Fix checked".



Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:

folders...

C:\Program Files\Common files\updmgr
C:\PROGRA~1\PERFEC~1
C:\Program Files\MyWay

-

Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're ' in use', try deleting them from " Safe Mode".



Post back a new log, and let me know how everything goes.
Steve
No Events found!

Top