Could expert check my HiJackThis log please?

Discussion in 'Malware Help (A Specialist Will Reply)' started by JADPadgett, Feb 22, 2006.

  1. JADPadgett

    JADPadgett Private E-2

    I have been at my wits end with my computer constantly skipping, both music, video, the cursor etc when I open any program or switch windows. I have run all spy and adaware programs in both normal and safe mode, and norton anti-virus but it doesnt seem to affect it. However, when i boot into safe mode or using diagnostic startup through msconfig the skipping ceases.

    If someone could check my HJT log i'd appreciate it!

    Thanks

    James
     

    Attached Files:

  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Now scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://www-cache.wanadoo.co.uk:8080;ftp=http://www-cache.wanadoo.co.uk:8080
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

    O4 - HKLM\..\Run: [ICcontrol] C:\WINDOWS\iccontrol.exe

    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)

    O14 - IERESET.INF: START_PAGE_URL=http://www.virgin.net/

    O16 - DPF: {084F552D-19EB-4668-9788-984CBC781A8F} - http://survey.otxresearch.com/Preloader.dll
    O16 - DPF: {9CCE3B43-4DE0-4236-A84E-108CA848EE6A} (WebCam Control) - http://webcamnow.com/fs5/ax/ActiveXWebCam.cab
    O16 - DPF: {FCF289D4-0AC8-4ED8-BE31-E8AF09606AB5} (download_35mb_com.applet) - http://download.35mb.com/images/downloadapplet.cab

    Again, make sure ALL browser windows are closed when you click FIX.

    Now, Please boot into Safe Mode, be sure you have the Viewing of Hidden Files & Folders Enabled per the tutorial. Now, navigate to and DELETE the following if they should remain:

    C:\WINDOWS\iccontrol.exe

    Next, run CCleaner to clean up cookies and temp files.

    Run full scans with Ad-Aware SE & Spybot S&D and have both programs fix what they find.

    Note: Remember to get all updates before doing the scans.


    After you complete the above, please reboot into Normal Mode and run the below online scans...

    After you complete the two above scans, attach the logs with a fresh HJT log.
     
  3. JADPadgett

    JADPadgett Private E-2

    Hi,

    Many thanks for your help, I have followed your instructions, please find attachments as per your request.

    Thanks

    James
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download Pocket KillBox
    • Save it to your desktop or a place easy to find.
    • Do not run it yet
    Next, run CCleaner to clean up cookies and temp files.

    Now, Please boot into Safe Mode, be sure you have the Viewing of Hidden Files & Folders Enabled per the tutorial. Now, navigate to and DELETE the following if they should remain:

    C:\Program Files\Norton Internet Security\Norton
    AntiVirus\Quarantine Delete everything in this folder!


    Locate PocketKillbox
    (Procede with this step even if they do not show in blue)

    Now, Copy and Paste C:\WINDOWS\system32\actskn45.ocx into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your PC to reboot.

    • If you get an error message about Pending Operations, just reboot your computer manually.
    After you complete the above, let me know how things are running and if any problems remain.
     
  5. JADPadgett

    JADPadgett Private E-2

    Hi,

    Many thanks for your continuing efforts.

    I have just completed doing what your instructions outline yet the problem remains. My computer loads. I'll first of all open iTunes. Start playing music, no problem. As soon as I then open another program (FireFox typically) the computer goes into skip mode. The music suffers from chronic skipping whilst the program loads and the mouse will move jumpily for a bit. The program that's opening now takes a lot longer to open than normal. Once the program has loaded, the skipping stops, until I try and open another program or start switching between programs.

    The same is true even if I don't open iTunes and just say open Adobe Acrobat.

    Thanks again

    James
     
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If your not having any further malware issues I would recommend posting those issues in the Software Forum. Those guys will get you fixed up.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds