A little help please? :)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by CaNoFzOo, May 20, 2004.

  1. CaNoFzOo

    CaNoFzOo Sergeant Major

    Yes I know you all probably get very tired of analyzing HijackThis logs. Please take a look though. Thank you sooo much :) -CaNoFzOo <3

    Logfile of HijackThis v1.97.7
    Scan saved at 4:18:45 PM, on 5/20/2004
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\WINDOWS\system32\pctspk.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\wanmpsvc.exe
    C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\America Online 8.0c\waol.exe
    C:\Program Files\America Online 8.0c\shellmon.exe
    C:\Program Files\America Online 8.0c\aolwbspd.exe
    C:\HijackThis.exe
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
    O9 - Extra button: Real.com (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/7d90ae05585062/housecall.antivirus.com/housecall/xscan53.cab
    O16 - DPF: {89D75D39-5531-47BA-9E4F-B346BA9C362C} (CWDL_DownLoadControl Class) - http://www.callwave.com/include/cab/CWDL_DownLoad.CAB
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38049.3372106481
    O17 - HKLM\System\CCS\Services\Tcpip\..\{02507D95-409E-49CB-8530-B71E0216A61B}: NameServer = 198.81.17.134
    O17 - HKLM\System\CS1\Services\Tcpip\..\{02507D95-409E-49CB-8530-B71E0216A61B}: NameServer = 198.81.17.134
     
  2. CaNoFzOo

    CaNoFzOo Sergeant Major

    :( Can someone please help me? It would be very appreciated.
     
  3. CaNoFzOo

    CaNoFzOo Sergeant Major

    lol thank you :)
     
  4. CaNoFzOo

    CaNoFzOo Sergeant Major

    ..just...bumping my thread to the top....
     
  5. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Well, were sort of sick of it only because if you have to ask, you probably should not be using it :) That said, using Google to research anything you dont recognize, OR posting ONLY items you dont recognize would be helpful and more time consuming. Delete AOL stuff, RealPlayer, Messenger for starters.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have HiJaak This fix the below line:

    O16 - DPF: {89D75D39-5531-47BA-9E4F-B346BA9C362C} (CWDL_DownLoadControl Class) - http://www.callwave.com/include/cab/CWDL_DownLoad.CAB

    And if your don't need those items that Major mentioned, uninstall them and then have HiJaak This fix anything left of AOL, RealPlayer, or Messenger.
     
  7. CaNoFzOo

    CaNoFzOo Sergeant Major

    Probably shouldn't be using it? I find some things wrong with that statement. I understand that you get tons of hijack this logs each and everyday. But Hijack this is a tool to help people remove unnesacary stuff on their computer and find the bad files right? Well, this IS a help forum, and this IS a section of the forum where you can post your hijack this logs. ALSO, the comment "If you have to ask you probably should not be using it" rubbed me the wrong way. At least people are asking before fixing everything they think is wrong in their Hijack this logs. I'm not trying to nag you or anything but.... what you had said in the first sentence makes me NOT want to ask for help.

    -CaNoFzOo

    Thanks for the replies.
     
  8. NonSuch

    NonSuch Private E-2

    You haven't stated what your problem is, and I'm sure that you must be having one or you wouldn't be concerned, which you obviously are...... and that's understandable.

    I do see that neither Win XP nor IE6 have service packs installed. An unpatched OS and/or browser is a magnet for malware. You may have picked up a virus and/or Trojan. I would suggest that you do an online virus scan at Trend Micro http://housecall.trendmicro.com/housecall/start_corp.asp and a Trojan scan at Sygate http://scan.sygatetech.com/pretrojanscan.html and let them clean out anything they find.

    Then you need to go to the Windows Update site to download and install ALL critical updates, which will probably take you some time and require rebooting and returning to the site multiple times, but it really needs to be done.

    Good luck to you.


     
  9. CaNoFzOo

    CaNoFzOo Sergeant Major

    Yeah... I always forget to install the critical updates. :eek: It takes like an hour to download them. I'm taking care of that right now. Thank you for your help. The reason I have posted my log in the first place was to see if everything was ok. I'm not having any problems with my computer (That I know of...yet:eek: ) Thanks for your all of your help!

    -CaNoFzOo :)
     
  10. CaNoFzOo

    CaNoFzOo Sergeant Major

    I just got this message while trying to install a service pack.. what is this all about!?
     
  11. Adrynalyne

    Adrynalyne Guest

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What message? Did you forget to post it?
     
  13. Adrynalyne

    Adrynalyne Guest

    No, it was there, she removed it :confused:

    It was a screenshot of the exact error listed in the KB article.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Oh! OK! Now I understand your message!
     
  15. Adrynalyne

    Adrynalyne Guest

    Ya, it does look a little out of place now that the screenshot is missing.
     
  16. CaNoFzOo

    CaNoFzOo Sergeant Major

    Lol yeah sorry guys... for some reason I wasn't comfortable with the screenshot being up. lol Don't ask..I'm just weird like that ^__^

    -CaNoFzOo.
     
  17. Adrynalyne

    Adrynalyne Guest

    LOL, your post said it all.

    No worries though.

    We have people actually call Microsoft with that error and play coy about it :)

    We don't care either. No alarm is sounded; no SWAT team is assembled ;)
     
  18. Adrynalyne

    Adrynalyne Guest

    Eh, replace coy with innocent.

    I hate this 3 minute post edit timer.
     
  19. CaNoFzOo

    CaNoFzOo Sergeant Major

    *Sigh* I hate it too. Did they just start the whole 3 minute post edit timer thingy? Or has it always been like that? :confused:
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Me three! But if people go back and edit posts at too much later an interval, the individual most interested will most likely miss the edits. And most people don't highlight their edits.
     
  21. Adrynalyne

    Adrynalyne Guest

    Relatively new.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds