Your Ad Here Your Ad Here
Results 1 to 3 of 3

Thread: Hijackthis

  1. #1
    ashutosh_cool16's Avatar Internet Addict
    Join Date
    Sep 2002
    Location
    Home
    Age
    32
    Posts
    278
    I installed this new software called Hijack This! which is a spyware detection and removal software.. I scanned my system.... and the log file is as follows...



    Logfile of HijackThis v1.97.7
    Scan saved at 7:21:17 PM, on 6/16/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    E:\WINDOWS\System32\smss.exe
    E:\WINDOWS\system32\winlogon.exe
    E:\WINDOWS\system32\services.exe
    E:\WINDOWS\system32\lsass.exe
    E:\WINDOWS\system32\svchost.exe
    E:\WINDOWS\System32\svchost.exe
    E:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
    E:\WINDOWS\system32\spoolsv.exe
    E:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    E:\WINDOWS\system32\crypserv.exe
    E:\WINDOWS\System32\inetsrv\inetinfo.exe
    E:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    E:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
    E:\WINDOWS\System32\svchost.exe
    E:\WINDOWS\Explorer.EXE
    E:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
    C:\BITWARE\NT\bwprnmon.exe
    E:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Creative\WebCam Monitor\TrayMon.exe
    E:\WINDOWS\system32\ntvdm.exe
    E:\WINDOWS\System32\rundll32.exe
    E:\Program Files\GoogleDCC\GoogleDCC.exe
    E:\Program Files\GoogleDCC\GoogleFah\GoogleFah.exe
    E:\Program Files\GoogleDCC\GoogleFah\GoogleFahCore_65.exe
    E:\Program Files\Messenger\msmsgs.exe
    E:\Program Files\Internet Explorer\iexplore.exe
    E:\Downloads\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://172.16.1.1/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/...://my.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=219.65.104.222:80
    O1 - Hosts: 66.159.18.16 www1.ndhosting.com
    O1 - Hosts: 66.159.18.16 www3.ndhosting.com
    O1 - Hosts: 66.159.18.16 www2.ndhosting.com
    O1 - Hosts: 66.159.18.16 www.ndhosting.com
    O1 - Hosts: 66.159.18.16 www.kinghost.com
    O1 - Hosts: 66.159.18.16 kinghost.com
    O1 - Hosts: 66.159.18.16 www1.kinghost.com
    O1 - Hosts: 66.159.18.16 www2.kinghost.com
    O1 - Hosts: 66.159.18.16 www3.kinghost.com
    O1 - Hosts: 66.159.18.16 www4.kinghost.com
    O1 - Hosts: 66.159.18.16 www5.kinghost.com
    O1 - Hosts: 66.159.18.16 www6.kinghost.com
    O1 - Hosts: 66.159.18.16 www7.kinghost.com
    O1 - Hosts: 66.159.18.16 www8.kinghost.com
    O1 - Hosts: 66.159.18.16 www9.kinghost.com
    O1 - Hosts: 66.159.18.16 www10.kinghost.com
    O1 - Hosts: 66.159.18.16 www.smutserver.com
    O1 - Hosts: 66.159.18.16 smutserver.com
    O1 - Hosts: 66.159.18.16 www1.smutserver.com
    O1 - Hosts: 66.159.18.16 www2.smutserver.com
    O1 - Hosts: 66.159.18.16 www16.smutserver.com
    O1 - Hosts: 66.159.18.16 www3.smutserver.com
    O1 - Hosts: 66.159.18.16 www4.smutserver.com
    O1 - Hosts: 66.159.18.16 www5.smutserver.com
    O1 - Hosts: 66.159.18.16 www6.smutserver.com
    O1 - Hosts: 66.159.18.16 www7.smutserver.com
    O1 - Hosts: 66.159.18.16 www8.smutserver.com
    O1 - Hosts: 66.159.18.16 www9.smutserver.com
    O1 - Hosts: 66.159.18.16 www10.smutserver.com
    O1 - Hosts: 66.159.18.16 www11.smutserver.com
    O1 - Hosts: 66.159.18.16 www12.smutserver
    O2 - BHO: (no name) - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - E:\Program Files\DAP\DAPBHO.dll
    O2 - BHO: (no name) - {0096CC0A-623C-4829-AD9C-19AF0DC9D8FE} - E:\Program Files\DAP\DAPIEBar.dll
    O2 - BHO: BPK IE Plugin - {1E1B2879-88FF-11D3-8D96-D7ACAC95951F} - E:\Program Files\Interpon D Worldwide Portfolio\IK\web.dll
    O2 - BHO: (no name) - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - E:\Program Files\NewDotNet\newdotnet6_30.dll
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - e:\windows\googletoolbar.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - E:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - E:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - E:\Program Files\DAP\DAPIEBar.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - e:\windows\googletoolbar.dll
    O4 - HKLM\..\Run: [EM_EXEC] E:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
    O4 - HKLM\..\Run: [bwprnmon.exe] C:\BITWARE\NT\bwprnmon.exe
    O4 - HKLM\..\Run: [ccApp] E:\Program Files\Common Files\Symantec Shared\ccApp.exe
    O4 - HKLM\..\Run: [ccRegVfy] E:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
    O4 - HKLM\..\Run: [WebCam Monitor] C:\Program Files\Creative\WebCam Monitor\TrayMon.exe
    O4 - HKLM\..\Run: [NeroCheck] E:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [New.net Startup] rundll32 E:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s
    O4 - HKLM\..\Run: [TimeSink Ad Client] "E:\Program Files\TimeSink\AdGateway\tsadbot.exe"
    O4 - HKCU\..\Run: [GoogleDCClient] E:\Program Files\GoogleDCC\GoogleDCC.exe -startup
    O8 - Extra context menu item: &Download with &DAP - E:\PROGRA~1\DAP\dapextie.htm
    O8 - Extra context menu item: &Google Search - res://E:\WINDOWS\GoogleToolbar.dll/cmsearch.html
    O8 - Extra context menu item: Backward &Links - res://E:\WINDOWS\GoogleToolbar.dll/cmbacklinks.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://E:\WINDOWS\GoogleToolbar.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Si&milar Pages - res://E:\WINDOWS\GoogleToolbar.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://E:\WINDOWS\GoogleToolbar.dll/cmtrans.html
    O9 - Extra button: Run DAP (HKLM)
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O9 - Extra button: NeoTrace It! (HKCU)
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O12 - Plugin for .mp3: E:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
    O12 - Plugin for .mpeg: E:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
    O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha...t/c381/chat.cab
    O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/game...s/y/potc_x.cab
    O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstall...ay_img=marsspan
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
    O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{027443F7-BFAB-4B60-A47E-E62A53120046}: NameServer = 172.16.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\..\{1F3200F3-42D6-4D0B-B7F6-A2CB9220E987}: NameServer = 172.16.1.1
    O17 - HKLM\System\CS1\Services\Tcpip\..\{027443F7-BFAB-4B60-A47E-E62A53120046}: NameServer = 172.16.1.1



    I can fix the above files using the software. Please tell me which files are harmful and should be removed...
    [IMG]http://img272.echo.cx/img272/9836/band8sw.gif[IMG]

  2. Software & Hardware   -   #2
    zapjb's Avatar Computer Abuser BT Rep: +3
    Join Date
    Nov 2002
    Posts
    3,694
    Post this in the Hijack This! forum to get expert advice. Or here to get opinions.

  3. Software & Hardware   -   #3
    Poster
    Join Date
    Jun 2003
    Posts
    126
    Originally posted by zapjb@16 June 2004 - 09:10
    Post this in the Hijack This! forum to get expert advice. Or here to get opinions.
    true, but if you would like to follow my opinion:

    uninstall new.net by using the control panel's add/remove programs. if it's not listed go here for instructions:
    Code:
    http://www.newdotnet.com/#remove
    make a new folder for hijack this. this is just for tidying purposes, as the backup files will clutter your download folder.

    rescan with hijack this and check the following:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...ch/search.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://172.16.1.1/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/cust...//my.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...ch/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com

    all 01 host entries

    O4 - HKLM\..\Run: [TimeSink Ad Client] "E:\Program Files\TimeSink\AdGateway\tsadbot.exe"

    this one is optional, but viewpoint has a dubious reputation:
    O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTS...y_img=marsspan

    close all browser windows and hit fix checked. reboot.

    delete this folder:
    E:\Program Files\TimeSink\

    your google toolbar may be compromised. uninstall the version you have, and download and install a new copy from here. keep in mind that using the page rank feature, is basically allowing google to spy on you, but that's up to you.
    Code:
    http://toolbar.google.com/
    reboot and post a new log when done.

    edit: i forgot--- are you the administrator on this computer?

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •