PDA

View Full Version : Hijackthis



ashutosh_cool16
06-16-2004, 03:05 PM
I installed this new software called Hijack This! which is a spyware detection and removal software.. I scanned my system.... and the log file is as follows...



Logfile of HijackThis v1.97.7
Scan saved at 7:21:17 PM, on 6/16/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
E:\WINDOWS\system32\crypserv.exe
E:\WINDOWS\System32\inetsrv\inetinfo.exe
E:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
E:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\Explorer.EXE
E:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\BITWARE\NT\bwprnmon.exe
E:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Creative\WebCam Monitor\TrayMon.exe
E:\WINDOWS\system32\ntvdm.exe
E:\WINDOWS\System32\rundll32.exe
E:\Program Files\GoogleDCC\GoogleDCC.exe
E:\Program Files\GoogleDCC\GoogleFah\GoogleFah.exe
E:\Program Files\GoogleDCC\GoogleFah\GoogleFahCore_65.exe
E:\Program Files\Messenger\msmsgs.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html (http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr/*http://www.yahoo.com/ext/search/search.html)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://172.16.1.1/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/...://my.yahoo.com (http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html (http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr/*http://www.yahoo.com/ext/search/search.html)
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com (http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com)
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=219.65.104.222:80
O1 - Hosts: 66.159.18.16 www1.ndhosting.com
O1 - Hosts: 66.159.18.16 www3.ndhosting.com
O1 - Hosts: 66.159.18.16 www2.ndhosting.com
O1 - Hosts: 66.159.18.16 www.ndhosting.com
O1 - Hosts: 66.159.18.16 www.kinghost.com
O1 - Hosts: 66.159.18.16 kinghost.com
O1 - Hosts: 66.159.18.16 www1.kinghost.com
O1 - Hosts: 66.159.18.16 www2.kinghost.com
O1 - Hosts: 66.159.18.16 www3.kinghost.com
O1 - Hosts: 66.159.18.16 www4.kinghost.com
O1 - Hosts: 66.159.18.16 www5.kinghost.com
O1 - Hosts: 66.159.18.16 www6.kinghost.com
O1 - Hosts: 66.159.18.16 www7.kinghost.com
O1 - Hosts: 66.159.18.16 www8.kinghost.com
O1 - Hosts: 66.159.18.16 www9.kinghost.com
O1 - Hosts: 66.159.18.16 www10.kinghost.com
O1 - Hosts: 66.159.18.16 www.smutserver.com
O1 - Hosts: 66.159.18.16 smutserver.com
O1 - Hosts: 66.159.18.16 www1.smutserver.com
O1 - Hosts: 66.159.18.16 www2.smutserver.com
O1 - Hosts: 66.159.18.16 www16.smutserver.com
O1 - Hosts: 66.159.18.16 www3.smutserver.com
O1 - Hosts: 66.159.18.16 www4.smutserver.com
O1 - Hosts: 66.159.18.16 www5.smutserver.com
O1 - Hosts: 66.159.18.16 www6.smutserver.com
O1 - Hosts: 66.159.18.16 www7.smutserver.com
O1 - Hosts: 66.159.18.16 www8.smutserver.com
O1 - Hosts: 66.159.18.16 www9.smutserver.com
O1 - Hosts: 66.159.18.16 www10.smutserver.com
O1 - Hosts: 66.159.18.16 www11.smutserver.com
O1 - Hosts: 66.159.18.16 www12.smutserver
O2 - BHO: (no name) - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - E:\Program Files\DAP\DAPBHO.dll
O2 - BHO: (no name) - {0096CC0A-623C-4829-AD9C-19AF0DC9D8FE} - E:\Program Files\DAP\DAPIEBar.dll
O2 - BHO: BPK IE Plugin - {1E1B2879-88FF-11D3-8D96-D7ACAC95951F} - E:\Program Files\Interpon D Worldwide Portfolio\IK\web.dll
O2 - BHO: (no name) - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - E:\Program Files\NewDotNet\newdotnet6_30.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - e:\windows\googletoolbar.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - E:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - E:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - E:\Program Files\DAP\DAPIEBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - e:\windows\googletoolbar.dll
O4 - HKLM\..\Run: [EM_EXEC] E:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [bwprnmon.exe] C:\BITWARE\NT\bwprnmon.exe
O4 - HKLM\..\Run: [ccApp] E:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] E:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [WebCam Monitor] C:\Program Files\Creative\WebCam Monitor\TrayMon.exe
O4 - HKLM\..\Run: [NeroCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 E:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s
O4 - HKLM\..\Run: [TimeSink Ad Client] "E:\Program Files\TimeSink\AdGateway\tsadbot.exe"
O4 - HKCU\..\Run: [GoogleDCClient] E:\Program Files\GoogleDCC\GoogleDCC.exe -startup
O8 - Extra context menu item: &Download with &DAP - E:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: &Google Search - res://E:\WINDOWS\GoogleToolbar.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://E:\WINDOWS\GoogleToolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://E:\WINDOWS\GoogleToolbar.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://E:\WINDOWS\GoogleToolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://E:\WINDOWS\GoogleToolbar.dll/cmtrans.html
O9 - Extra button: Run DAP (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O9 - Extra button: NeoTrace It! (HKCU)
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O12 - Plugin for .mp3: E:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O12 - Plugin for .mpeg: E:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha...t/c381/chat.cab (http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab)
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cab
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstall...ay_img=marsspan (https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/beta/vet_install_popup.pl?2&4&04.00.04.03&http://www.space.com/php/multimedia/zoomviewer/index.php?display_img=marsspan)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab (http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab)
O17 - HKLM\System\CCS\Services\Tcpip\..\{027443F7-BFAB-4B60-A47E-E62A53120046}: NameServer = 172.16.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{1F3200F3-42D6-4D0B-B7F6-A2CB9220E987}: NameServer = 172.16.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{027443F7-BFAB-4B60-A47E-E62A53120046}: NameServer = 172.16.1.1



I can fix the above files using the software. Please tell me which files are harmful and should be removed...

zapjb
06-16-2004, 04:02 PM
Post this in the Hijack This! forum to get expert advice. Or here to get opinions. :blink:

dopey
06-16-2004, 05:16 PM
Originally posted by zapjb@16 June 2004 - 09:10
Post this in the Hijack This! forum to get expert advice. Or here to get opinions. :blink:
true, but if you would like to follow my opinion:

uninstall new.net by using the control panel's add/remove programs. if it's not listed go here for instructions:

http://www.newdotnet.com/#remove

make a new folder for hijack this. this is just for tidying purposes, as the backup files will clutter your download folder. ;)

rescan with hijack this and check the following:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://172.16.1.1/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/...://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com

all 01 host entries

O4 - HKLM\..\Run: [TimeSink Ad Client] "E:\Program Files\TimeSink\AdGateway\tsadbot.exe"

this one is optional, but viewpoint has a dubious reputation:
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstall...ay_img=marsspan

close all browser windows and hit fix checked. reboot.

delete this folder:
E:\Program Files\TimeSink\

your google toolbar may be compromised. uninstall the version you have, and download and install a new copy from here. keep in mind that using the page rank feature, is basically allowing google to spy on you, but that's up to you.

http://toolbar.google.com/

reboot and post a new log when done.

edit: i forgot--- are you the administrator on this computer?