Hijack This LOG, please help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by nickson2, Apr 28, 2004.

  1. nickson2

    nickson2 Master Sergeant

    Does anyone know if theres anything on this logfile, that i can safely get shut of, that may be stopping me from viewing a particular website?
    Thanks in advance.

    Logfile of HijackThis v1.97.7
    Scan saved at 11:27:29, on 27/04/2004

    Platform: Windows XP (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

    C:\Program Files\Alwil Software\Avast4\ashServ.exe

    C:\WINDOWS\Explorer.EXE

    C:\PROGRA~1\Program Team Cash\Mags64.exe

    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

    C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe

    C:\WINDOWS\System32\ctfmon.exe

    C:\Program Files\MSN Messenger\msnmsgr.exe

    C:\Program Files\Microsoft Office\Office\Osa.exe

    C:\Program Files\Microsoft Office\Office\Findfast.exe

    C:\Program Files\blueyonder IST\bin\mpbtn.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe

    C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe

    C:\unzipped\hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.blueyonder.co.uk/

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by blueyonder

    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    O4 - HKLM\..\Run: [Chin Balm] C:\PROGRA~1\Program Team Cash\Mags64.exe

    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

    O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe

    O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe

    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe

    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background

    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    O4 - HKLM\..\RunOnce: [DELDIR0.EXE] "C:\DOCUME~1\EARTHL~1\LOCALS~1\Temp\DELDIR0.EXE" "C:\Program Files\McAfee\McAfee Shared Components\Guardian\"

    O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE

    O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE

    O4 - Global Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\matcli.exe

    O9 - Extra button: Messenger (HKLM)

    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)

    O9 - Extra button: Freeserve (HKCU)

    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

    O16 - DPF: Win32 Classes -

    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

    O16 - DPF: {4C2C81B4-91DA-494D-8DBF-A7846BA07073} (Mini Jeeves Installer Control) - http://www.ask.co.uk/toolbar/download/MiniJv-inst.cab

    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37705.5374189815

    O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.blueyonder.co.uk/assets/tool/files/MotivePreQual.cab

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

     
  2. alanc

    alanc MajorGeek

    Do you know what this is?
    O4 - HKLM\..\Run: [Chin Balm] C:\PROGRA~1\Program Team Cash\Mags64.exe

    Fix this:
    O16 - DPF: Win32 Classes -

    This shouldn't be there, looks like a McAfee thing but I doubt it. I would fix it:
    O4 - HKLM\..\RunOnce: [DELDIR0.EXE] "C:\DOCUME~1\EARTHL~1\LOCALS~1\Temp\DELDIR0.EXE" "C:\Program Files\McAfee\McAfee Shared Components\Guardian\"


    Other than that it looks OK to me.
     
  3. nickson2

    nickson2 Master Sergeant

    Thanks Alanc+

    I assume i just delete the first, but how do i fix 016 - DPF: Win32 Classes
    and this 04-HKLM thing
     
  4. alanc

    alanc MajorGeek

    I don't know what to do with the first one because I don't know what it is. That's why I asked you. It could be a nasty or a harmless program.

    For the other two, in HJT, put checks in those lines and click 'Fix checked'
     
  5. nickson2

    nickson2 Master Sergeant

    thanks i too dont know wot the first is so i will get shut and see....
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds