|
#1
|
||||
|
||||
|
Hi, I am new to this forum. I just downloaded Hijack This, but have no idea how to use it. To give a little background on my problem, we have two computers connected by a network. I am currently on our Gateway, which obviously still has internet.
The problem is with the other computer, an HP Pavilion. A couple of days ago we had a sudden problem with our Anti virus program (Anti-Vir free edition) popping up and saying there was spyware/adware in this new dot net file. It kept popping up whenever we did anything on the computer, and when we told it to delete the file, it said that it had put it in quarantine, and didn't give us any other options. But it wouldn't stop warning us about it, so finally I temporarily disabled the anti-vir(to get it to let me do anything), and manually deleted the new dot net file. I didn't remember downloading it in the first place, and didn't think there was any harm in deleting it. Well, after restarting the computer, our internet connection was totally gone, but our network still works!I sort of saw how you used the Hijack This files on here, so I downloaded it on this computer, sent the program up to the HP Pavilion, and scanned it. I have pasted the log below. I hope someone can help me! Thanks!Logfile of HijackThis v1.99.1 Scan saved at 11:32:20 AM, on 9/19/05 Platform: Windows 98 SE (Win9x 4.10.2222A) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\SPOOL32.EXE C:\WINDOWS\SYSTEM\MPREXE.EXE C:\WINDOWS\SYSTEM\MSTASK.EXE c:\windows\SYSTEM\KB891711\KB891711.EXE C:\WINDOWS\SYSTEM\HIDSERV.EXE C:\WINDOWS\SYSTEM\MSGLOOP.EXE C:\WINDOWS\SYSTEM\MSG32.EXE C:\WINDOWS\SYSTEM\mmtask.tsk C:\WINDOWS\EXPLORER.EXE C:\WINDOWS\TASKMON.EXE C:\WINDOWS\SYSTEM\SYSTRAY.EXE C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXE C:\WINDOWS\SYSTEM\HPSYSDRV.EXE C:\PROGRAM FILES\DIRECTCD\DIRECTCD.EXE C:\WINDOWS\SYSTEM\USBMMKBD.EXE C:\WINDOWS\SYSTEM\STIMON.EXE C:\PROGRAM FILES\AVPERSONAL\AVGCTRL.EXE C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE C:\WINDOWS\RunDLL.exe C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\KEYBDMGR.EXE C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE C:\WINDOWS\SYSTEM\HPLAMPC.EXE C:\WINDOWS\SYSTEM\WMIEXE.EXE C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMUSBKB2.EXE C:\PROGRAM FILES\YAHOO!\MESSENGER\YMSGR_TRAY.EXE C:\PROGRAM FILES\HIJACKTHIS.EXE R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/sidesearch.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.begin2search.com/sidesearch.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.begin2search.com/sidesearch.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.wowway.com/portal/index.asp?RG=MI R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/sidesearch.html R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/sidesearch.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by PeoplePC R3 - Default URLSearchHook is missing F1 - win.ini: run=hpfsched O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.websearch.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.websearch.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.websearch.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.websearch.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O1 - Hosts: 216.130.185.143 websearch.com O1 - Hosts: 216.130.185.143 www.adwave.com O1 - Hosts: 216.130.185.143 adwave.com O1 - Hosts: 216.130.185.143 www.xzoomy.com O1 - Hosts: 216.130.185.143 xzoomy.com O1 - Hosts: 216.130.185.143 www.advnt01.com O1 - Hosts: 216.130.185.143 advnt01.com O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\PROGRAM FILES\YAHOO!\COMMON\YIETAGBM.DLL O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRAM FILES\YAHOO!\COMMON\YIESRVC.DLL O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN0\YT.DLL O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe O4 - HKLM\..\Run: [SystemTray] SysTray.Exe O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\Run: [Keyboard Manager] C:\Program Files\Netropa\One-touch Multimedia Keyboard\MMKeybd.exe O4 - HKLM\..\Run: [HPScanPatch] C:\WINDOWS\SYSTEM\HPScanFix.exe O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [Adaptec DirectCD] C:\Program Files\DirectCD\DIRECTCD.EXE O4 - HKLM\..\Run: [USBMMKBD] usbmmkbd.exe O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe O4 - HKLM\..\Run: [AVGCtrl] C:\PROGRAM FILES\AVPERSONAL\AVGCTRL.EXE /min O4 - HKLM\..\Run: [stcinstaller] c:\installer\id53.exe O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe O4 - HKLM\..\RunServices: [Hidserv] Hidserv.exe run O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE" O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet O8 - Extra context menu item: Check &Spelling - res://C:\PROGRAM FILES\IESPELL\IESPELL.DLL/SPELLCHECK.HTM O8 - Extra context menu item: &ieSpell Options - res://C:\PROGRAM FILES\IESPELL\IESPELL.DLL/SPELLOPTION.HTM O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR3.DLL/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR3.DLL/cmwordtrans.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR3.DLL/cmcache.html O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR3.DLL/cmsimilar.html O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR3.DLL/cmbacklinks.html O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR3.DLL/cmtrans.html O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O9 - Extra button: Guide - {A6E07A80-436A-11d3-83B6-00902747E82E} - c:\windows\system\shdocvw.dll O9 - Extra button: PeoplePC - {A6E07A82-436A-11d3-83B6-00902747E82E} - c:\windows\PeoplePC\hta\peopledialer.hta O9 - Extra button: Wallet - {F05B7DAE-337E-11D3-83B6-00E0980647AC} - C:\WINDOWS\PEOPLEPC\BIN\PAYMEN~1.DLL O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\PROGRAM FILES\IESPELL\IESPELL.DLL O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\PROGRAM FILES\IESPELL\IESPELL.DLL O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\PROGRAM FILES\IESPELL\IESPELL.DLL O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\PROGRAM FILES\IESPELL\IESPELL.DLL O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\PROGRAM FILES\HELLO\PICASACAPTURE.DLL O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\PROGRAM FILES\HELLO\PICASACAPTURE.DLL O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRAM FILES\YAHOO!\COMMON\YIESRVC.DLL O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_38.dll' missing O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - https://www.broderbund.com/IFW/Cabs/isetup.cab O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab O16 - DPF: {10000000-1000-0000-1000-000000000000} - mhtml:file://C:\ARCHIVE.MHT!http://65.75.141.230/msits.exe O16 - DPF: {5E943D9C-F8DC-4258-8E3F-A61BB3405A33} (ZingBatchAXDwnl Class) - http://www.imagestation.com/common/c...on=4,3,2,20802 O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab O16 - DPF: {2042B57E-6336-459E-B7CE-2A0F6C9E6AF8} (IEPlayInterface Class) - http://www.lotrdvd.com/dvdkey/extend...s/iaieplay.dll O16 - DPF: {51045741-8C4E-4EAC-8F03-08E43A6FBB29} - http://c.ancestry.com/cab/aft/AncestryFamilyTree.cab O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifescapeinc.com/inst...l/pinstall.cab O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/...ampx_en_dl.cab |
|
#2
|
||||
|
||||
|
__________________
Microsoft MVP 2008: 2009: Windows - Shell/User Please do not PM me or email me asking for support. Post on the forums instead so everyone can gain from the solution. Patience is a virtue--yes your problem is urgent, but so are the problems of the other members. Our time spent at CTH is free, but hosting CTH costs money. Help us help you, and donate here. |
![]() |
| Bookmarks |
«
Previous Topic
|
Next Topic
»
| Topic Tools | |
|
|
All times are GMT +1. The time now is 10:50 AM.
[
RSS ]



The problem is with the other computer, an HP Pavilion. A couple of days ago we had a sudden problem with our Anti virus program (Anti-Vir free edition) popping up and saying there was spyware/adware in this new dot net file. It kept popping up whenever we did anything on the computer, and when we told it to delete the file, it said that it had put it in quarantine, and didn't give us any other options. But it wouldn't stop warning us about it, so finally I temporarily disabled the anti-vir(to get it to let me do anything), and manually deleted the new dot net file. I didn't remember downloading it in the first place, and didn't think there was any harm in deleting it. Well, after restarting the computer, our internet connection was totally gone, but our network still works!
Thanks!



