Go Back   Cyber Tech Help Support Forums > Operating Systems > Older Windows Versions > Windows XP

Notices

Windows XP Problem solving for the Windows XP Operating System

Reply
 
Topic Tools
  #1  
Old March 6th, 2004, 06:18 PM
mickb mickb is offline
Senior Member
 
Join Date: Oct 2002
Age: 62
Posts: 288
suspected virus

Hi everyone

I think there is a virus on this machine how do i find hijack this to send it to you

Michael
Reply With Quote
  #2  
Old March 6th, 2004, 06:25 PM
dammit's Avatar
dammit dammit is offline
Rampant Rabbit
 
Join Date: Dec 2002
Location: New York/Paris/Milan/pie country
Age: 22
Posts: 11,532
http://www.spywareinfo.com/~merijn/files/hijackthis.zip
http://www.majorgeeks.com/download.php?det=3155
http://www.sherrylynn.us/HijackThis.exe

Reply With Quote
  #3  
Old March 6th, 2004, 06:26 PM
mickb mickb is offline
Senior Member
 
Join Date: Oct 2002
Age: 62
Posts: 288
Quote:
Originally Posted by mickb
Hi everyone

I think there is a virus on this machine how do i find hijack this to send it to you

Michael
Hi IT'S ME AGAIN FOUND IT
Logfile of HijackThis v1.97.7
Scan saved at 17:25:04, on 06/03/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
C:\WINDOWS\REGEDIT.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AOL 8.0\waol.exe
C:\Program Files\AOL 8.0\shellmon.exe
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\YVWVABUT\HijackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.freeserve.com/iesearch/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://tutie.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.freeserve.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Freeserve
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .aif: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...ctor/swdir.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...tatsClient.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...702.0754398148
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{40FCD4EC-CD91-4B19-BDA8-D834F2FECA0F}: NameServer = 195.93.50.134
Any help would be good

Michael
Reply With Quote
  #4  
Old March 6th, 2004, 07:36 PM
dammit's Avatar
dammit dammit is offline
Rampant Rabbit
 
Join Date: Dec 2002
Location: New York/Paris/Milan/pie country
Age: 22
Posts: 11,532
Hi buddy....it looks ok to me Is your AV reporting one?
Reply With Quote
  #5  
Old March 6th, 2004, 07:38 PM
MainFrame's Avatar
MainFrame MainFrame is offline
Banned
 
Join Date: Nov 2003
Location: Norway
Age: 35
Posts: 621
Do a free housecall scan, then tell us if it's found anything.
Reply With Quote
  #6  
Old March 6th, 2004, 09:29 PM
mickb mickb is offline
Senior Member
 
Join Date: Oct 2002
Age: 62
Posts: 288
Quote:
Originally Posted by MainFrame
Nothing on Norton but it takes an age to load settings when logging on (aol user accounts also if I look at the cpu usage when logging on it reaches 100% at times. It tells me it is loading users settings but what settings use this amount of resources. This is my sisters comp and my nephew has been using Kazaa and the like.
Reply With Quote
  #7  
Old March 6th, 2004, 09:49 PM
MainFrame's Avatar
MainFrame MainFrame is offline
Banned
 
Join Date: Nov 2003
Location: Norway
Age: 35
Posts: 621
Try installing and running this.
If you have problems, check out www.merijn.org.
Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Topics
Topic Topic Starter Forum Replies Last Post
Suspected Virus blue_70517 Malware Removal 10 October 12th, 2010 01:50 AM
Suspected Virus Attack bocabill Malware Removal 41 December 19th, 2009 11:14 AM
suspected virus problem compnew90 Malware Removal 13 July 16th, 2009 12:31 PM
suspected virus stephenmcg101 Malware Removal 1 August 14th, 2007 12:54 AM
Suspected Virus?? Vince_Lim Applications 3 June 13th, 2007 09:01 AM


All times are GMT +1. The time now is 05:54 AM.